CVE-2020-36837: ThemeGrill Demo Importer 1.3.4 - 1.6.1 - Authorization Bypass to Site Reset
The ThemeGrill Demo Importer plugin for WordPress is vulnerable to authentication bypass due to a missing capability check on the resetwizardactions function in versions 1.3.4 through 1.6.1. This makes it possible for authenticated attackers to reset the WordPress database. After which, if there is a user named 'admin', the attacker will become automatically logged in as an administrator.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-36837?
CVE-2020-36837 has been classified as a critical vulnerability due to its potential to allow authenticated attackers to reset the WordPress database.
How do I fix CVE-2020-36837?
To fix CVE-2020-36837, update the ThemeGrill Demo Importer plugin to version 1.6.2 or later.
Who is affected by CVE-2020-36837?
CVE-2020-36837 affects users of the ThemeGrill Demo Importer plugin for WordPress versions 1.3.4 through 1.6.1.
What exploit is associated with CVE-2020-36837?
CVE-2020-36837 can be exploited by authenticated attackers to bypass authentication and reset the WordPress database.
Is there a workaround for CVE-2020-36837?
A temporary workaround for CVE-2020-36837 is to disable the ThemeGrill Demo Importer plugin until it can be updated.