One Click Demo Import
One Click Demo Import has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2022 and 2024; all 2 are fixed as of September 2026. Their average CVSS score is 7.2, and the most serious one scores 7.2 out of 10. Severity breakdown: 0 critical and 2 high.
The most common weakness is Deserialization Of Untrusted Data, behind 1 of the records (50%). Other recurring categories include Unrestricted Upload Of File With Dangerous Type.
Every one of the 2 issues recorded for One Click Demo Import has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. One Click Demo Import is installed on roughly 1,000,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2024-34433One Click Demo Import <= 3.2.0 - Authenticated (Admin+) PHP Object Injection
Read the full analysisVulnerability Records

One Click Demo Import
Author
Syed Balkhi
The best feature of this plugin is, that theme authors can define import files in their themes and so all you (the user of the theme) have to do is click on the “Import Demo Data” button. Are you a theme author? Setup One Click Demo Imports for your theme and your users will thank you for it! Follow this easy guide on how to setup this plugin for your themes! Are you a theme user? Contact the author of your theme and let them know about this plugin. Theme authors can make any theme compatible with this plugin in 15 minutes and make it much more user-friendly. “Where can I find the theme author contact?“ Please take a look at our plugin documentation for more information on how to import your demo content. This plugin is using the modified version of the improved WP import 2.0 that is still in development and can be found here: https://github.com/humanmade/WordPress-Importer. NOTE: There is no setting to “connect” authors from the demo import file to the existing users in your WP site (like there is in the original WP Importer plugin). All demo content will be imported under the current user. Do you want to contribute? Please refer to our official GitHub repository.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C