CVE · High

CVE-2022-29451 — Rara One Click Demo Import [rara-one-click-demo-import] < 1.3.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-29451 Rara One Click Demo Import [rara-one-click-demo-import] < 1.3.0 Cross-Site Request Forgery (CSRF) High 8.8 < 1.3.0 1.3.0 2022-04-21

CVE-2022-29451

The Rara One Click Demo Import plugin through version 1.2.9 contains a cross-site request forgery vulnerability that can be exploited to perform arbitrary file uploads. An attacker can craft a malicious request that, when executed by a logged-in administrator, uploads files to the /wp-content/uploads/ directory without proper authorization checks. This flaw requires social engineering to trick an admin user into visiting a malicious page but could allow an attacker to upload dangerous files to the WordPress installation. The vulnerability was addressed in version 1.3.0.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.