What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) leading to Arbitrary File Upload vulnerability in Rara One Click Demo Import plugin <= 1.2.9 on WordPress allows attackers to trick logged-in admin users into uploading dangerous files into /wp-content/uploads/ directory.
Explanation of Vulnerability in Simple Terms
02Summary
The Rara One Click Demo Import WordPress plugin through version 1.2.9 is vulnerable to cross-site request forgery (CSRF). An attacker can craft a malicious webpage that, when visited by a logged-in WordPress admin, performs unauthorized actions on the site without the admin's knowledge or consent. This could allow the attacker to import malicious demo content or modify site settings.
What an attacker can do
03Attacker Capabilities
Trick a logged-in admin into importing malicious demo content or changing site settings without their consent.
Potential impact on your site
04Site Impact
Unauthorized demo imports or site configuration changes could deface your site, inject malware, or compromise user data.
Conditions required to exploit
05Prerequisites
Admin must visit a malicious webpage while logged into WordPress. No special plugin configuration required.
Key dates
06Disclosure timeline
April 29, 2022
CVE published
April 28, 2026
Record updated