Impact
The Mizan Demo Importer plugin contains a missing authorization flaw that allows an attacker to invoke its import functionality without proper privileges. This weakness, identified as CWE‑862, means that any user who can reach the import interface can trigger it and potentially upload or activate demo content, leading to unauthorized data manipulation or site compromise.
Affected Systems
Product: Mizan Themes Mizan Demo Importer plugin. Affected before and including version 0.1.3. No further version data available.
Risk and Exploitability
The vulnerability scores a CVSS of 5.4, indicating moderate severity, while its EPSS score of less than 1% suggests a low likelihood of exploitation in the current landscape. It is not listed in the CISA KEV catalog. The attack surface is most likely a publicly accessible WordPress site where the plugin is active; an adversary could exploit the lack of access control by crafting a request to the import endpoint. Successful exploitation would grant unauthorized access to the import capability, which could be leveraged for broader site misuse.
OpenCVE Enrichment