What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in Themely Theme Demo Import.This issue affects Theme Demo Import: from n/a through 1.1.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Unrestricted Upload of File with Dangerous Type vulnerability in Themely Theme Demo Import.This issue affects Theme Demo Import: from n/a through 1.1.1.
Explanation of Vulnerability in Simple Terms
Theme Demo Import allows authenticated administrators to upload files without proper validation. An attacker with admin privileges can upload malicious files that affect the entire site, including reading sensitive data, modifying content, or disrupting service. The vulnerability requires high-level access but has broad impact across the WordPress installation.
What an attacker can do
Upload malicious files to read data, modify content, or disable the site.
Potential impact on your site
A compromised admin account can be used to upload files that compromise your entire site.
Conditions required to exploit
Attacker must have administrator-level access to the WordPress site.
Key dates
External resources
Related vulnerabilities