CVE · High

CVE-2024-34433 — One Click Demo Import [one-click-demo-import] < 3.2.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-34433 One Click Demo Import [one-click-demo-import] < 3.2.1 Deserialization of Untrusted Data High 7.2 < 3.2.1 3.2.1 2024-05-07

CVE-2024-34433

The One Click Demo Import plugin through version 3.2.0 contains a PHP Object Injection vulnerability caused by unsafe deserialization of untrusted data. Attackers with Administrator-level permissions can inject malicious PHP objects, though exploitation depends on the presence of a gadget chain from other installed plugins or themes. If such a chain exists on the system, an attacker could execute arbitrary code, exfiltrate sensitive information, or remove files. The vulnerability has been fixed in version 3.2.1.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.