Beta

Report

HashThemes Demo Importer <= 1.1.1 is vulnerable to Improper Access Control allowing content deletion vulnerability

Subscriber
Published
2021-10-25

The Hashthemes Demo Importer Plugin for WordPress contained several AJAX functions which relied on a nonce which was visible to all logged-in users for access control in versions up to, and including 1.1.1. This made it possible for authenticated attackers with minimal permissions, such as a subscriber, to execute a function that dropped nearly all a sites database tables and removed the contents of wp-content/uploads.

CVSS

Score:8.1

Severity:High

Version: 1.1.1

There is a patch available in v1.1.2 and we strongly recommend you update to this version as soon as possible.