Unauthorized Database Reset Vulnerability in Blaze Demo Importer Plugin for WordPress
CVE-2025-13334

8.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
12 December 2025

What is CVE-2025-13334?

The Blaze Demo Importer plugin for WordPress has a critical vulnerability due to its lack of capability checks in the 'blaze_demo_importer_install_demo' function. This deficiency allows authenticated users, even those with basic subscriber privileges, to perform unauthorized database resets. The potential impact includes truncating database tables indiscriminately (excluding critical tables such as options, usermeta, and users), which can lead to significant data loss. Additionally, attackers could delete sidebar widgets, modify theme settings, and erase content from the uploads directory, severely compromising the integrity and functionality of WordPress sites utilizing this plugin.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Blaze Demo Importer 1.0.0 <= 1.0.13

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kenneth Dunn
.