PT-2025-42280 · WordPress · Demo Import Kit

Published

2025-10-15

·

Updated

2025-10-15

·

CVE-2025-10051

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Demo Import Kit plugin for WordPress versions prior to 1.1.1
Description The Demo Import Kit plugin for WordPress is susceptible to arbitrary file uploads because of a lack of file type validation during the import process. This allows authenticated attackers with Administrator-level access or higher to upload arbitrary files to the server, potentially leading to remote code execution.
Recommendations Update the Demo Import Kit plugin to version 1.1.1 or later.

Fix

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-10051

Affected Products

Demo Import Kit