Showing 2 vulnerabilities on this page for themegrill_demo_importer

Signals CISA KEV Ransomware Nuclei
ThemeGrill vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

ThemeGrill Demo Importer 1.3.4 - 1.6.1 - Authorization Bypass to Site Reset

The ThemeGrill Demo Importer plugin for WordPress is vulnerable to authentication bypass due to a missing capability check on the reset_wizard_actions function in versions 1.3.4 through 1.6.1. This makes it possible for authenticated attackers to reset the WordPress database. After which, if there is a user named 'admin', the attacker will become automatically logged in as an administrator.

CWE-862Oct 16, 2024
CVSS9.9v3.1EPSS0.584%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

themegrill themegrill_demo_importer Missing Authentication for Critical Function

themegrill-demo-importer before 1.6.2 does not require authentication for wiping the database, because of a reset_wizard_actions hook.

CWE-306May 5, 20211 related artifact
CVSS9.1v3.1EPSS4.11%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX