CVE-2020-36333
themegrill themegrill_demo_importer Missing Authentication for Critical Function
Record summary
CVE-2020-36333 has a selected CVSS score of 9.1 (critical); EIP currently links 1 Nuclei template.
Description
themegrill-demo-importer before 1.6.2 does not require authentication for wiping the database, because of a reset_wizard_actions hook.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Feb 16, 2020 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
themegrill_demo_importerBrowse themegrill / themegrill_demo_importer | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICALThemeGrill Demo Importer < 1.6.2 - Database ResetCVSS 9.1
ThemeGrill Demo Importer before 1.6.2 does not require authentication for wiping the database due to a reset_wizard_actions hook. In versions 1.3.4 and above and versions 1.6.1 and below, there is a vulnerability that allows any unauthenticated user to wipe the entire database to its default state after which they are automatically logged in as an administrator.
Impact
Unauthenticated attackers can wipe the entire WordPress database to its default state and gain automatic administrator access, resulting in complete site takeover and data loss.
Remediation
Upgrade to ThemeGrill Demo Importer version 1.6.2 or later.
Source: ProjectDiscovery