ThemeGrill Vulnerabilities and Affected Products
Vulnerabilities associated with themegrill_demo_importer.
Products
Clear product- ColorMag3 vulnerabilities
- Masteriyo - LMS3 vulnerabilities
- Himalayas2 vulnerabilities
- Maintenance Page2 vulnerabilities
- ThemeGrill Demo Importer2 vulnerabilities
- themegrill_demo_importer2 vulnerabilities
- User Registration2 vulnerabilities
- User Registration Stripe2 vulnerabilities
- Zakra2 vulnerabilities
- Accelerate1 vulnerability
- ColorNews1 vulnerability
- Esteem1 vulnerability
- maintenance_page1 vulnerability
- Registration Form for WooCommerce1 vulnerability
- Spacious1 vulnerability
- ThemeGrill Demo Importer plugin for WordPress1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2020-36837CRITICAL | ThemeGrill Demo Importer 1.3.4 - 1.6.1 - Authorization Bypass to Site ResetThe ThemeGrill Demo Importer plugin for WordPress is vulnerable to authentication bypass due to a missing capability check on the reset_wizard_actions function in versions 1.3.4 through 1.6.1. This makes it possible for authenticated attackers to reset the WordPress database. After which, if there is a user named 'admin', the attacker will become automatically logged in as an administrator. CWE-862Oct 16, 2024 | CVSS9.9v3.1 | EPSS0.584% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-36333CRITICAL | themegrill themegrill_demo_importer Missing Authentication for Critical Functionthemegrill-demo-importer before 1.6.2 does not require authentication for wiping the database, because of a reset_wizard_actions hook. | CVSS9.1v3.1 | EPSS4.11% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |