Unauthorized Plugin Installation Vulnerability in Blaze Demo Importer Plugin for WordPress
CVE-2025-8446
4.3MEDIUM
What is CVE-2025-8446?
The Blaze Demo Importer plugin for WordPress has a vulnerability that allows authenticated attackers, including users with Subscriber-level access and above, to initiate unauthorized installations of a limited number of plugins. This issue arises from a missing capability check within the 'blaze_demo_importer_install_plugin' function. To exploit this vulnerability, the News Kit Elementor Addons plugin and a specific BlazeThemes theme need to be activated.
Affected Version(s)
Blaze Demo Importer * <= 1.0.12