CVE-2025-14364 affects the Demo Importer Plus plugin for WordPress, specifically versions up to and including 2.0.8. This vulnerability allows authenticated attackers with subscriber-level access to trigger a full site reset, deleting most database tables and re-running the WordPress installation process, which then grants the attacker administrator privileges. Rated 8.8 HIGH on CVSS, the vulnerability has a low attack complexity and can lead to complete data loss and privilege escalation. There is currently no public exploit code available, nor is there evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 2.0.8CPE match | cpe:2.3:a:kraftplugins:demo_importer_plus:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.