CVE-2025-14364: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-14364 is a missing authorization vulnerability in the Demo Importer Plus plugin for WordPress (by Kraftplugins) that allows authenticated attackers with Subscriber-level access or higher to trigger a full site reset and escalate privileges to Administrator. All versions up to and including 2.0.8 are affected. The vulnerability was published on December 18, 2025, with Wordfence credited as the assigning authority. It carries a CVSS v3.1 base score of 8.8 (High) (Wordfence, Red Hat CVE).

Technical details

The root cause is a missing capability check (CWE-862) on the Ajax::handle_request() function within the Demo Importer Plus plugin. Because no authorization validation is performed before executing sensitive operations, any authenticated user — including those with the lowest default WordPress role (Subscriber) — can invoke this AJAX handler. Exploitation involves sending a crafted authenticated AJAX request that triggers a full site reset: all database tables except users and usermeta are dropped, wp_install() is re-executed, and the attacking account is automatically assigned the Administrator role. A public proof-of-concept has been published on GitHub (GitHub PoC, Wordfence).

Impact

Successful exploitation results in complete compromise of the WordPress site across all three security dimensions: confidentiality (attacker gains Administrator access to all site content and credentials), integrity (all non-user database tables are dropped and the site is re-initialized), and availability (the entire site is effectively reset, causing total data loss for posts, pages, settings, and plugin configurations). The attacker's subscriber account is automatically elevated to Administrator, enabling persistent access, further lateral movement within the hosting environment, and potential installation of backdoors or malicious plugins (Wordfence Blog).

Exploitability

As of the time of reporting, there is no confirmed evidence of in-the-wild exploitation, and no threat actor attribution has been made. A public proof-of-concept exploit was published on GitHub, increasing the risk of opportunistic attacks. The EPSS score is approximately 0.039% (very low), and the vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Qualys has added detection for this vulnerability (detection ID 530769) (Qualys, GitHub PoC).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Demo Importer Plus plugin (versions ≤ 2.0.8) using tools like WPScan, Shodan, or by inspecting plugin directories on target sites.
  2. Account Registration: Register or obtain a low-privilege account (Subscriber level or above) on the target WordPress site — many sites allow open registration.
  3. Authenticate: Log in to the WordPress site with the Subscriber-level account and obtain a valid authentication nonce or session cookie.
  4. Craft Malicious AJAX Request: Send an authenticated HTTP POST request to the WordPress AJAX endpoint (/wp-admin/admin-ajax.php) targeting the Ajax::handle_request() function of the Demo Importer Plus plugin, with the appropriate action parameter to trigger the site reset functionality.
  5. Trigger Site Reset: The unprotected handler executes, dropping all database tables except users and usermeta, then calls wp_install() to reinitialize the WordPress installation.
  6. Privilege Escalation: The wp_install() process automatically assigns the Administrator role to the attacking subscriber account, granting full administrative control of the site.
  7. Post-Exploitation: With Administrator access, install backdoors, create additional admin accounts, exfiltrate data, or pivot to the underlying server (GitHub PoC, Wordfence).

Indicators of compromise

  • Network: Authenticated POST requests to /wp-admin/admin-ajax.php from low-privilege user accounts with action parameters associated with the Demo Importer Plus plugin's reset functionality; unusual AJAX calls from subscriber-level sessions.
  • Logs: WordPress access logs showing POST requests to admin-ajax.php from subscriber accounts followed immediately by site re-initialization activity; database error logs indicating mass table drops.
  • Database: Sudden disappearance of all WordPress tables except wp_users and wp_usermeta; presence of a freshly initialized WordPress database structure (default tables recreated with new timestamps).
  • User Accounts: Unexpected elevation of a subscriber-level user account to Administrator role in wp_usermeta (meta_key wp_capabilities set to a:1:{s:13:"administrator";b:1;}).
  • File System: New or modified WordPress core files consistent with a fresh wp_install() execution; unexpected changes to wp-config.php or site options.

Mitigation and workarounds

Update the Demo Importer Plus plugin to a version beyond 2.0.8, which includes the fix adding proper capability checks to the Ajax::handle_request() function (the patch is available in the plugin's SVN changeset) (WordPress SVN). If an immediate update is not possible, temporarily deactivate or remove the plugin to eliminate the attack surface. Additionally, disable open user registration on the WordPress site to prevent unauthenticated users from obtaining the Subscriber-level access required for exploitation, and implement a Web Application Firewall (WAF) rule to block unauthorized AJAX requests targeting the plugin's handler (Wordfence Blog).

Community reactions

Wordfence reported that over 10,000 WordPress sites were protected against this vulnerability through their firewall, highlighting the broad exposure of the affected plugin (Wordfence Blog). The vulnerability was included in Wordfence's weekly WordPress vulnerability report for December 15, 2025 – January 4, 2026, and was also referenced in The Hacker News' weekly security recap (The Hacker News). The CISA published a vulnerability bulletin (SB25-356) covering the week of December 15, 2025, which included this CVE (CISA Bulletin). Community coverage on platforms like Mastodon and Bluesky noted the severity of the privilege escalation impact.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management