7.2
CVSSv3

CVE-2022-1538

Published: 16/01/2024 Updated: 19/01/2024
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 0

Vulnerability Summary

Theme Demo Import WordPress plugin prior to 1.1.1 does not validate the imported file, allowing high-privilege users such as admin to upload arbitrary files (such as PHP) even when FILE_MODS and FILE_EDIT are disallowed.

Vulnerable Product Search on Vulmon Subscribe to Product

themely theme demo import