WordPress Rara One Click Demo Import plugin <= 1.2.9 - Cross-Site Request Forgery (CSRF) leads to Arbitrary File Upload vulnerability
Vulnerable versions
<= 1.2.9
PSID
2b11ff6bf679
Classification
Cross Site Request Forgery (CSRF)
OWASP Top 10
A8: Cross Site Request Forgery (CSRF)
Required privilege
Publicly disclosed
2022-04-21
Patchstack vPatch available since
09.12.2021
Details
Cross-Site Request Forgery (CSRF) leads to Arbitrary File Upload vulnerability discovered in Rara One Click Demo Import plugin (versions <= 1.2.9) by BEE-K.
Solution
Update the WordPress Rara One Click Demo Import plugin to the latest available version (at least 1.3.0).
References
Plugin page
Changelog