Unauthorized Database Reset Vulnerability in Blaze Demo Importer Plugin for WordPress
CVE-2025-13334
What is CVE-2025-13334?
The Blaze Demo Importer plugin for WordPress has a critical vulnerability due to its lack of capability checks in the 'blaze_demo_importer_install_demo' function. This deficiency allows authenticated users, even those with basic subscriber privileges, to perform unauthorized database resets. The potential impact includes truncating database tables indiscriminately (excluding critical tables such as options, usermeta, and users), which can lead to significant data loss. Additionally, attackers could delete sidebar widgets, modify theme settings, and erase content from the uploads directory, severely compromising the integrity and functionality of WordPress sites utilizing this plugin.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Blaze Demo Importer 1.0.0 <= 1.0.13
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved