PT-2026-3354 · WordPress · Demo Importer Plus

Lorenzo Franchini

·

Publicado

2026-01-17

·

Atualizado

2026-01-22

·

CVE-2025-14478

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Demo Importer Plus plugin for WordPress versions up to and including 2.0.9
Description The software is susceptible to XML External Entity Injection (XXE) through the SVG file upload functionality. This allows authenticated attackers with Author-level access or higher to potentially achieve code execution in vulnerable configurations. This issue only impacts sites using PHP versions older than 8.0.
Recommendations Update the Demo Importer Plus plugin to a version newer than 2.0.9. For sites using PHP versions older than 8.0, consider alternative methods for importing demos that do not involve SVG file uploads.

Correção

XXE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-14478

Produtos afetados

Demo Importer Plus