PT-2025-50816 · WordPress · Blaze Demo Importer

Kenneth Dunn

·

Published

2025-12-12

·

Updated

2025-12-17

·

CVE-2025-13334

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Blaze Demo Importer plugin for WordPress versions through 1.0.13
Description The Blaze Demo Importer plugin for WordPress is susceptible to unauthorized database resets and file deletion. This is due to a missing capability check within the blaze demo importer install demo() function. Authenticated attackers with subscriber-level access or higher can truncate all database tables (excluding options, usermeta, and users), delete sidebar widgets, theme modifications, and content within the uploads folder.
Recommendations Update the Blaze Demo Importer plugin to a version beyond 1.0.13.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-13334

Affected Products

Blaze Demo Importer