Impact
The Demo Import Kit plugin for WordPress suffers from missing file type validation that permits the upload of any file through its import feature. This flaw is a classic example of CWE‑434. An authenticated attacker with Administrator privileges can upload arbitrary files, potentially including malicious scripts or executables, thereby enabling remote code execution on the affected server.
Affected Systems
The vulnerability affects all installations of the Demo Import Kit plugin from the themeinwp vendor, specifically any version up to and including 1.1.0.
Risk and Exploitability
The flaw carries a CVSS score of 7.2, indicating high severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation at this time. It is not listed in the CISA KEV catalog. The attack vector is inferred to be a local authenticated user with Administrator privileges; the absence of file type checks allows the attacker to deposit executable content that can be later triggered to run server‑side.
OpenCVE Enrichment