Crafthemes Demo Import
Crafthemes Demo Import has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2024; 1 is fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 8.0, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 2 high. 2024 was the busiest year with 2 disclosures.
The most common weakness is Missing Authorization, behind 1 of the records (50%). Other recurring categories include Unrestricted Upload Of File With Dangerous Type.
1 of the records (50%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2024.
2 independent researchers contributed these findings, one record each. Crafthemes Demo Import is installed on roughly 400 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2024-9698Crafthemes Demo Import <= 3.3 - Authenticated (Admin+) Arbitrary File Upload in process_uploaded_files
Read the full analysisVulnerability Records

Crafthemes Demo Import
Author
Crafthemes
Import Crafthemes Demo content. Copyright Crafthemes Demo Import WordPress Plugin Crafthemes Demo Import is distributed under the terms of the GNU GPL This program is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 2 of the License, or (at your option) any later version. This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details. Crafthemes Demo Import bundles the following third-party resources: One Click Demo Import v2.5.2, Copyright 2019 License: GPLv3 or later Source: https://github.com/proteusthemes/one-click-demo-import
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C