CVE-2020-36334: CSRF
Published May 5, 2021
·Updated
themegrill-demo-importer before 1.6.3 allows CSRF, as demonstrated by wiping the database.
Affected Software
1 affected component
themegrill Themegrill Demo Importer Wordpress<1.6.3
Remediation
Patch Available
Event History
May 5, 2021
CVE Published
via MITRE·03:11 AM
Data Sourced
via MITRE·03:11 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-36334?
CVE-2020-36334 has a high severity due to its potential for CSRF attacks that can wipe the database.
2
How do I fix CVE-2020-36334?
To fix CVE-2020-36334, update the ThemeGrill Demo Importer plugin to version 1.6.3 or higher.
3
What type of vulnerability is CVE-2020-36334?
CVE-2020-36334 is a Cross-Site Request Forgery (CSRF) vulnerability.
4
Who is affected by CVE-2020-36334?
Users of ThemeGrill Demo Importer versions before 1.6.3 are affected by CVE-2020-36334.
5
Can CVE-2020-36334 lead to data loss?
Yes, CVE-2020-36334 can lead to complete database loss if exploited.