PT-2025-52211 · WordPress · Wordpress Demo Importer Plus

Angus Girvan

·

Published

2025-12-18

·

Updated

2025-12-18

·

CVE-2025-14364

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WordPress Demo Importer Plus plugin versions through 2.0.8
Description The software contains a flaw that allows unauthorized modification of data, data loss, and privilege escalation. A missing capability check within the handle request() function enables authenticated attackers with Subscriber-level access or higher to trigger a complete site reset, dropping all database tables except users and usermeta. The reset process also re-runs wp install(), granting the attacking subscriber account Administrator privileges.
Recommendations Update WordPress Demo Importer Plus plugin to a version beyond 2.0.8.

Fix

LPE

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-14364

Affected Products

Wordpress Demo Importer Plus