CVE-2021-39333: Hashthemes Demo Importer <= 1.1.1 Improper Access Control Allowing Content Deletion
The Hashthemes Demo Importer Plugin <= 1.1.1 for WordPress contained several AJAX functions which relied on a nonce which was visible to all logged-in users for access control, allowing them to execute a function that truncated nearly all database tables and removed the contents of wp-content/uploads.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-39333?
CVE-2021-39333 is considered a critical vulnerability due to its potential to truncate database tables.
How do I fix CVE-2021-39333?
To fix CVE-2021-39333, update the Hashthemes Demo Importer Plugin to the latest version beyond 1.1.1.
What systems are affected by CVE-2021-39333?
CVE-2021-39333 affects WordPress sites using Hashthemes Demo Importer Plugin version 1.1.1 and earlier.
What are the potential impacts of CVE-2021-39333?
The potential impacts of CVE-2021-39333 include loss of database content and site instability due to data truncation.
Who is vulnerable to CVE-2021-39333?
Any WordPress site running the Hashthemes Demo Importer Plugin version 1.1.1 or earlier is vulnerable to CVE-2021-39333.