Sparkle Demo Importer
Sparkle Demo Importer has one disclosed vulnerability in the WordSec catalog, all reported in 2024; it is fixed as of September 2026. Their average CVSS score is 6.5, and the most serious one scores 6.5 out of 10.
The most common weakness is Missing Authorization, behind 1 of the records (100%).
The one issue recorded for Sparkle Demo Importer has a vendor fix available, so running the current release closes it.
All of these findings were reported by Lucio Sá. Sparkle Demo Importer is installed on roughly 5,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.2.11.
CVE-2024-6120Sparkle Demo Importer <= 1.4.7 - Missing Authorization to Authorized(Subscriber+) Post/Pages/Attachements Deletion and Demo Data Import
Read the full analysisVulnerability Records

Sparkle Demo Importer
Author
Sparkle WP
Home | Docs | Premium | All themes | Plugins | Blog Sparkle Demo Importer imports sparkle themes full demo with just one click. It is specially developed for demo import purpose. This plugin works for theme developed by SparleThemes and if other themes wants to use then they have to use action filter to work. You just need to define the array that includes the location of the demo zip files and other related info. Get the outstanding themes from Sparkle Themes __ Check all of our Free themes __ Educenter Construction Light AppZend Sparkle Store BuzzStore MetroStore Online eStore Educenter Xpert __ Check all of our Premium plugins __ Construction Plus AppZend Pro Educenter Pro Sparkle Store Pro Online eStore Pro Chankhe Plus BuzzStore Pro FitnessPark Pro Blogger Buzz Pro Medical Heed Pro MetroStore Pro Features Import Complete Demo Data Automatic Install Required Plugins Import Widgets Data Import Customizer Data Reset Site Credits * Forked from HashThemes Demo Importer Plugin
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C