CVE Database /
CVE-2020-36837
CVE · Critical
CVE-2020-36837 — Starter Templates & Sites Pack by ThemeGrill [themegrill-demo-importer] >= 1.3.4 - <= 1.6.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2020-36837
|
Starter Templates & Sites Pack by ThemeGrill [themegrill-demo-importer] >= 1.3.4 - <= 1.6.1 |
Missing Authorization |
Critical
9.9
|
1.3.4–1.6.1
|
1.6.1 |
2020-02-16 |
—
|
CVE-2020-36837
The ThemeGrill Demo Importer plugin through version 1.6.1 contains an authentication bypass vulnerability where the reset_wizard_actions function fails to verify user capabilities before execution. This flaw allows any authenticated user to trigger a database reset, and if an admin account named 'admin' exists, the attacker gains automatic administrative access upon completion of the reset process.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings