Di Themes Demo Site Importer
Di Themes Demo Site Importer has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for Di Themes Demo Site Importer has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by Trương Hữu Phúc (truonghuuphuc). Di Themes Demo Site Importer is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.6.7.
CVE-2025-58914Di Themes Demo Site Importer <= 1.2 - Cross-Site Request Forgery
Read the full analysisVulnerability Records

Di Themes Demo Site Importer
Author
Di Themes
Di Themes Demo Site Importer plugin can be used to import the demo website developed by Di Themes. To import a demo website, Open: ‘Appearance > Import Demo’ and follow simple steps. Di Themes Demo Site Importer plugin will import contents like post types, widgets, customize settings and set the pages and settings according to the settings of the demo website. It simply makes the demo website importing tasks easier.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C