CVE · Critical

CVE-2020-36837 — Starter Templates & Sites Pack by ThemeGrill [themegrill-demo-importer] >= 1.3.4 - <= 1.6.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2020-36837 Starter Templates & Sites Pack by ThemeGrill [themegrill-demo-importer] >= 1.3.4 - <= 1.6.1 Missing Authorization Critical 9.9 1.3.4–1.6.1 1.6.1 2020-02-16

CVE-2020-36837

The ThemeGrill Demo Importer plugin through version 1.6.1 contains an authentication bypass vulnerability where the reset_wizard_actions function fails to verify user capabilities before execution. This flaw allows any authenticated user to trigger a database reset, and if an admin account named 'admin' exists, the attacker gains automatic administrative access upon completion of the reset process.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.