
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14364 is a missing authorization vulnerability in the Demo Importer Plus plugin for WordPress (by Kraftplugins) that allows authenticated attackers with Subscriber-level access or higher to trigger a full site reset and escalate privileges to Administrator. All versions up to and including 2.0.8 are affected. The vulnerability was published on December 18, 2025, with Wordfence credited as the assigning authority. It carries a CVSS v3.1 base score of 8.8 (High) (Wordfence, Red Hat CVE).
The root cause is a missing capability check (CWE-862) on the Ajax::handle_request() function within the Demo Importer Plus plugin. Because no authorization validation is performed before executing sensitive operations, any authenticated user — including those with the lowest default WordPress role (Subscriber) — can invoke this AJAX handler. Exploitation involves sending a crafted authenticated AJAX request that triggers a full site reset: all database tables except users and usermeta are dropped, wp_install() is re-executed, and the attacking account is automatically assigned the Administrator role. A public proof-of-concept has been published on GitHub (GitHub PoC, Wordfence).
Successful exploitation results in complete compromise of the WordPress site across all three security dimensions: confidentiality (attacker gains Administrator access to all site content and credentials), integrity (all non-user database tables are dropped and the site is re-initialized), and availability (the entire site is effectively reset, causing total data loss for posts, pages, settings, and plugin configurations). The attacker's subscriber account is automatically elevated to Administrator, enabling persistent access, further lateral movement within the hosting environment, and potential installation of backdoors or malicious plugins (Wordfence Blog).
As of the time of reporting, there is no confirmed evidence of in-the-wild exploitation, and no threat actor attribution has been made. A public proof-of-concept exploit was published on GitHub, increasing the risk of opportunistic attacks. The EPSS score is approximately 0.039% (very low), and the vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Qualys has added detection for this vulnerability (detection ID 530769) (Qualys, GitHub PoC).
/wp-admin/admin-ajax.php) targeting the Ajax::handle_request() function of the Demo Importer Plus plugin, with the appropriate action parameter to trigger the site reset functionality.users and usermeta, then calls wp_install() to reinitialize the WordPress installation.wp_install() process automatically assigns the Administrator role to the attacking subscriber account, granting full administrative control of the site./wp-admin/admin-ajax.php from low-privilege user accounts with action parameters associated with the Demo Importer Plus plugin's reset functionality; unusual AJAX calls from subscriber-level sessions.admin-ajax.php from subscriber accounts followed immediately by site re-initialization activity; database error logs indicating mass table drops.wp_users and wp_usermeta; presence of a freshly initialized WordPress database structure (default tables recreated with new timestamps).wp_usermeta (meta_key wp_capabilities set to a:1:{s:13:"administrator";b:1;}).wp_install() execution; unexpected changes to wp-config.php or site options.Update the Demo Importer Plus plugin to a version beyond 2.0.8, which includes the fix adding proper capability checks to the Ajax::handle_request() function (the patch is available in the plugin's SVN changeset) (WordPress SVN). If an immediate update is not possible, temporarily deactivate or remove the plugin to eliminate the attack surface. Additionally, disable open user registration on the WordPress site to prevent unauthenticated users from obtaining the Subscriber-level access required for exploitation, and implement a Web Application Firewall (WAF) rule to block unauthorized AJAX requests targeting the plugin's handler (Wordfence Blog).
Wordfence reported that over 10,000 WordPress sites were protected against this vulnerability through their firewall, highlighting the broad exposure of the affected plugin (Wordfence Blog). The vulnerability was included in Wordfence's weekly WordPress vulnerability report for December 15, 2025 – January 4, 2026, and was also referenced in The Hacker News' weekly security recap (The Hacker News). The CISA published a vulnerability bulletin (SB25-356) covering the week of December 15, 2025, which included this CVE (CISA Bulletin). Community coverage on platforms like Mastodon and Bluesky noted the severity of the privilege escalation impact.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."