WordPress Plugin Vulnerabilities

Access Demo Importer < 1.0.7 - Subscriber+ Arbitrary File Upload

Description

Versions up to, and including, 1.0.6, of the Access Demo Importer WordPress plugin are vulnerable to arbitrary file uploads via the plugin_offline_installer AJAX action due to a missing capability check in the plugin_offline_installer_callback functionfound in the ~/inc/demo-functions.php file along with insufficient file validation.

Proof of Concept

Affects Plugins

Fixed in 1.0.7

References

Miscellaneous

Original Researcher
Chloe Chamberland
Submitter
Chloe Chamberland
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2021-10-06 (about 4 years ago)
Added
2021-10-06 (about 4 years ago)
Last Updated
2022-04-09 (about 4 years ago)

Other