CVE-2025-14478 | Demo Importer Plus Plugin up to 2.0.9/8.0 on WordPress SVG File Parser xml external entity reference (EUVD-2026-3148)
A vulnerability categorized as problematic has been discovered in Demo Importer Plus Plugin up to 2.0.9/8.0 on WordPress. The affected element is an unknown function of the component SVG File Parser. The manipulation results in xml external entity reference.
This vulnerability is reported as CVE-2025-14478. The attack can be launched remotely. No exploit exists.
It is advisable to upgrade the affected component.