10,000 WordPress Sites Protected Against Site Reset and Privilege Escalation Vulnerability in Demo Importer Plus WordPress Plugin
We urge users to update their sites with the latest patched version of Demo Importer Plus, version 2.0.9 at the time of this publication, as soon as possible.
wordfence.com/blog/2026/01/1…
On November 27th, 2025, we received a submission for a Site Reset and Privilege Escalation vulnerability in Demo Importer Plus, a WordPress plugin with more than 10,000 active installations.
This vulnerability can be leveraged to trigger a full site reset and assign the administrator role to the attacker’s account.
Props to shark3y (
@shark3yx) who discovered and responsibly reported this vulnerability through the Wordfence Bug Bounty Program. This researcher earned a bounty of $195.00 for this discovery.
Our mission is to secure WordPress through defense in depth, which is why we are investing in quality vulnerability research and collaborating with researchers of this caliber through our Bug Bounty Program.
We are committed to making the WordPress ecosystem more secure through the detection and prevention of vulnerabilities, which is a critical element to our multi-layered approach to security.
Wordfence Premium, Wordfence Care, and Wordfence Response users received a firewall rule to protect against any exploits targeting this vulnerability on December 10, 2025.
Sites using the free version of Wordfence will receive the same protection 30 days later on January 9, 2026.
We provided full disclosure details to the Codewing Solutions team instantly through our Wordfence Vulnerability Management Portal on December 9, 2025.
The vendor acknowledged the report and released the patch on December 16, 2025.
We would like to commend the Codewing Solutions team for their prompt response and timely patch.
#wordpress #wordpresssecurity #wordpresssecuritynews
ALT 10,000 WordPress Sites Protected Against Site Reset and Privilege Escalation Vulnerability in Demo Importer Plus WordPress Plugin