CVE-2020-36837

ThemeGrill Demo Importer 1.3.4 - 1.6.1 - Authorization Bypass to Site Reset

criticalMissing Authorization
9.9
CVSS Score
9.9
CVSS Score
critical
Severity
1.6.2
Patched in
1704d
Time to patch

Description

The ThemeGrill Demo Importer plugin for WordPress is vulnerable to authentication bypass due to a missing capability check on the reset_wizard_actions function in versions 1.3.4 through 1.6.1. This makes it possible for authenticated attackers to reset the WordPress database. After which, if there is a user named 'admin', the attacker will become automatically logged in as an administrator.

CVSS Vector Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
High
Confidentiality
High
Integrity
High
Availability

Technical Details

Affected versions>=1.3.4 <=1.6.1
PublishedFebruary 16, 2020
Last updatedOctober 16, 2024

Check if your site is affected.

Run a free security audit to detect vulnerable plugins, outdated versions, and misconfigurations.