PostmagThemes Demo Import
PostmagThemes Demo Import has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2022; all 2 are fixed as of September 2026. Their average CVSS score is 7.2, and the most serious one scores 7.2 out of 10. Severity breakdown: 0 critical and 2 high. 2022 was the busiest year with 2 disclosures.
The most common weakness is Unrestricted Upload Of File With Dangerous Type, behind 2 of the records (100%).
Every one of the 2 issues recorded for PostmagThemes Demo Import has a vendor fix available, so running the current release closes all known holes.
All of these findings were reported by thunder.god.hhh. PostmagThemes Demo Import is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2022-1540PostmagThemes Demo Import <= 1.0.7 - Authenticated (Administrator+) Arbitrary File Upload
Read the full analysisVulnerability Records

PostmagThemes Demo Import
Author
postmagthemes
PostmagThemes Demo Import is a free demo importer WordPress plugin that lets you import the demo you desire in just a single click. This plugin allows user to select the author name while downloading post. Hence user can seperate the downloaded post to seperate user. The plugin works out of the box; all you have to do is install and activate the plugin and all the demos available on your currently used theme will be on your fingertips (visit Appearance=> Import Demo Data) Images Resources All images are licensed under Creative Commons Zero (CC0) license. * banner-772×250.jpg, banner-1544×500.jpg, icon-128×128.jpg, icon-256×256.jpg Self Created – CCO
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C