CVE-2020-36837
ThemeGrill Demo Importer 1.3.4 - 1.6.1 - Authorization Bypass to Site Reset
criticalMissing Authorization
9.9
CVSS Score
9.9
CVSS Score
critical
Severity
1.6.2
Patched in
1704d
Time to patch
Description
The ThemeGrill Demo Importer plugin for WordPress is vulnerable to authentication bypass due to a missing capability check on the reset_wizard_actions function in versions 1.3.4 through 1.6.1. This makes it possible for authenticated attackers to reset the WordPress database. After which, if there is a user named 'admin', the attacker will become automatically logged in as an administrator.
CVSS Vector Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HAttack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
High
Confidentiality
High
Integrity
High
Availability
Technical Details
Affected versions
>=1.3.4 <=1.6.1PublishedFebruary 16, 2020
Last updatedOctober 16, 2024
Affected pluginthemegrill-demo-importer
Check if your site is affected.
Run a free security audit to detect vulnerable plugins, outdated versions, and misconfigurations.