9.9
CVE-2020-36837
- EPSS 0.36%
- Veröffentlicht 16.10.2024 07:15:08
- Zuletzt bearbeitet 16.10.2024 16:38:14
- Quelle security@wordfence.com
- CVE-Watchlists
- Unerledigt
ThemeGrill Demo Importer 1.3.4 - 1.6.1 - Authorization Bypass to Site Reset
The ThemeGrill Demo Importer plugin for WordPress is vulnerable to authentication bypass due to a missing capability check on the reset_wizard_actions function in versions 1.3.4 through 1.6.1. This makes it possible for authenticated attackers to reset the WordPress database. After which, if there is a user named 'admin', the attacker will become automatically logged in as an administrator.
Mögliche Gegenmaßnahme
Starter Templates & Sites Pack by ThemeGrill: Update to version 1.6.2, or a newer patched version
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Starter Templates & Sites Pack by ThemeGrill
Version
1.3.4-1.6.1
Daten sind bereitgestellt durch das CVE Programm von Authorized Data Publishers (ADP) (Unstrukturiert)
Herstellerthemegrill
≫
Produkt
themegrill_demo_importer
Default Statusunknown
Version <=
1.6.1
Version
1.3.4
Status
affected
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.36% | 0.572 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@wordfence.com | 9.9 | 3.1 | 6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
|
CWE-862 Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.