First published: Mon Nov 01 2021(Updated: )
The Hashthemes Demo Importer Plugin <= 1.1.1 for WordPress contained several AJAX functions which relied on a nonce which was visible to all logged-in users for access control, allowing them to execute a function that truncated nearly all database tables and removed the contents of wp-content/uploads.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hashthemes Hashthemes Demo Importer | <=1.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-39333 is considered a critical vulnerability due to its potential to truncate database tables.
To fix CVE-2021-39333, update the Hashthemes Demo Importer Plugin to the latest version beyond 1.1.1.
CVE-2021-39333 affects WordPress sites using Hashthemes Demo Importer Plugin version 1.1.1 and earlier.
The potential impacts of CVE-2021-39333 include loss of database content and site instability due to data truncation.
Any WordPress site running the Hashthemes Demo Importer Plugin version 1.1.1 or earlier is vulnerable to CVE-2021-39333.