HashThemes Demo Importer
HashThemes Demo Importer has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2021 and 2026; all 2 are fixed as of September 2026. Their average CVSS score is 7.3, and the most serious one scores 8.1 out of 10. Severity breakdown: 0 critical and 1 high.
The most common weakness is Cross-Site Scripting, behind 1 of the records (50%). Other recurring categories include Missing Authorization.
Every one of the 2 issues recorded for HashThemes Demo Importer has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. HashThemes Demo Importer is installed on roughly 6,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2021-39333HashThemes Demo Importer <= 1.1.1 - Missing Authorization to Database Wipe
Read the full analysisVulnerability Records

HashThemes Demo Importer
Author
hashthemes
HashThemes Demo Importer imports the full demo with just one click. It is specially developed to add a demo importer functionality in the theme developed by HashThemes but it can also be used by any other themes as well. You just need to define the array that includes the location of the demo zip files and other informations. The other information includes name of the demo, preview image, theme option array, menu array, home page and blog page slug(if any), required plugins array and the tags that categorizes the theme. The demo zip should contain the XML file, customizer (.dat) file, widget (.wie) file, theme option (.json), revolutions slider zip. It is not necessary to add all these files in the demo zip. You can skip the files if your demo does not need it. Features Reset website(Optional) Install recommended and required plugins automatically Imports Revolution slider Imports fully functional demo Video Guide
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C