Arbitrary File Uploads Vulnerability in Crafthemes Demo Import Plugin
CVE-2024-9698

7.2HIGH

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
14 December 2024

Summary

The Crafthemes Demo Import plugin for WordPress is exposed to a significant risk due to inadequate file type validation in the 'process_uploaded_files' function. All versions up to and including 3.3 are susceptible, enabling authenticated users with Administrator-level access or higher to upload arbitrary files. This can potentially lead to unauthorized execution of remote code on the affected site's server, increasing the threat level for exploitation.

Affected Version(s)

Crafthemes Demo Import * <= 3.3

References

EPSS Score

43% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Joshua Chan
.