CVE-2022-29451
The Rara One Click Demo Import plugin through version 1.2.9 contains a cross-site request forgery vulnerability that can be exploited to perform arbitrary file uploads. An attacker can craft a malicious request that, when executed by a logged-in administrator, uploads files to the /wp-content/uploads/ directory without proper authorization checks. This flaw requires social engineering to trick an admin user into visiting a malicious page but could allow an attacker to upload dangerous files to the WordPress installation. The vulnerability was addressed in version 1.3.0.
Based on public CVE data (MITRE/NVD).