CVE Database /
CVE-2022-23976
CVE · High
CVE-2022-23976 — Access Demo Importer [access-demo-importer] < 1.0.8 (closed)
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2022-23976
|
Access Demo Importer [access-demo-importer] < 1.0.8 (closed) |
Cross-Site Request Forgery (CSRF) |
High
8.1
|
< 1.0.8
|
1.0.8 |
2022-01-24 |
—
|
CVE-2022-23976
The Access Demo Importer plugin for WordPress through version 1.0.7 contains a Cross-Site Request Forgery vulnerability in its AJAX handler for the `adi_demo_data_reset` function because it fails to verify nonce tokens. An attacker can exploit this flaw to trick users into resetting all site data, including posts, pages, and media files. The vulnerability was fixed in version 1.0.8.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings