Impact
The Demo Importer Plus plugin for WordPress suffers from a missing capability check in its Ajax handler, allowing any authenticated user with at least Subscriber privileges to invoke a full site reset. This operation drops all database tables except those storing users and user metadata, re‑runs WordPress’s installation process, and in the process promotes the attacker's account to Administrator, thereby granting full control over the site.
Affected Systems
It affects the WordPress plugin Demo Importer Plus provided by kraftplugins, specifically all versions up to and including 2.0.8.
Risk and Exploitability
The CVSS score of 8.8 classifies the vulnerability as high severity, although the EPSS score of less than 1% indicates a very low probability of current exploitation. The vulnerability is not listed in CISA KEV. An attacker who is already authenticated as a Subscriber can trigger the exploit by sending a crafted Ajax request; the missing capability check permits execution without further privileges, leading to a complete site reset and privilege escalation to Administrator. Because of the severe impact on confidentiality, integrity, and availability, administrators should consider the vulnerability a high priority even though exploitation likelihood is low.
OpenCVE Enrichment