GHSA-32px-xrqr-6c5g
GitHub Security Advisory
⚠ Unreviewed
MODERATE
Has CVE
Advisory Details
The Blaze Demo Importer plugin for WordPress is vulnerable to unauthorized limited plugin install due to a missing capability check on the 'blaze_demo_importer_install_plugin' function in all versions up to, and including, 1.0.12. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install and activate a limited number of specific plugins. The News Kit Elementor Addons plugin and a BlazeThemes theme must be installed and activated in order to exploit the vulnerability.
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: September 22, 2025 6:29 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.