Lafka WordPress Theme Demo Import Vulnerability for Authenticated Users

Vulnerability

A vulnerability exists in the Lafka - Multi Store Burger - Pizza & Food Delivery WooCommerce Theme for WordPress, in all versions through 4.5.7. The issue arises from a missing capability check on the 'lafka_import_lafka' AJAX action, allowing authenticated users with Subscriber-level access and above to import demo data that can overwrite existing site content.

Impact

Exploitation of this vulnerability allows for unauthorized demo data import, which can overwrite existing site content.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
5.2
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.