CVE-2024-34433
The One Click Demo Import plugin through version 3.2.0 contains a PHP Object Injection vulnerability caused by unsafe deserialization of untrusted data. Attackers with Administrator-level permissions can inject malicious PHP objects, though exploitation depends on the presence of a gadget chain from other installed plugins or themes. If such a chain exists on the system, an attacker could execute arbitrary code, exfiltrate sensitive information, or remove files. The vulnerability has been fixed in version 3.2.1.
Based on public CVE data (MITRE/NVD).