Lafka WordPress Theme Demo Import Vulnerability for Authenticated Users
Vulnerability
A vulnerability exists in the Lafka - Multi Store Burger - Pizza & Food Delivery WooCommerce Theme for WordPress, in all versions through 4.5.7. The issue arises from a missing capability check on the 'lafka_import_lafka' AJAX action, allowing authenticated users with Subscriber-level access and above to import demo data that can overwrite existing site content.
Impact
Exploitation of this vulnerability allows for unauthorized demo data import, which can overwrite existing site content.
Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
0.6exploitability
5.2remediation
0.0relevance
0.0threat
0.0urgency
2.9incentive
1.7Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
