PT-2026-3354 · WordPress · Demo Importer Plus
Lorenzo Franchini
·
Publicado
2026-01-17
·
Atualizado
2026-01-22
·
CVE-2025-14478
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Demo Importer Plus plugin for WordPress versions up to and including 2.0.9
Description
The software is susceptible to XML External Entity Injection (XXE) through the SVG file upload functionality. This allows authenticated attackers with Author-level access or higher to potentially achieve code execution in vulnerable configurations. This issue only impacts sites using PHP versions older than 8.0.
Recommendations
Update the Demo Importer Plus plugin to a version newer than 2.0.9.
For sites using PHP versions older than 8.0, consider alternative methods for importing demos that do not involve SVG file uploads.
Correção
XXE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Demo Importer Plus