Report
The Hashthemes Demo Importer Plugin for WordPress contained several AJAX functions which relied on a nonce which was visible to all logged-in users for access control in versions up to, and including 1.1.1. This made it possible for authenticated attackers with minimal permissions, such as a subscriber, to execute a function that dropped nearly all a sites database tables and removed the contents of wp-content/uploads.
Score:8.1
Severity:High
Version: 1.1.1
There is a patch available in v1.1.2 and we strongly recommend you update to this version as soon as possible.