Description
WordPress Plugin HashThemes Demo Importer is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently completely reset a site, permanently deleting nearly all database content as well as all uploaded media. WordPress Plugin HashThemes Demo Importer version 1.1.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.1.2 or latest
References
Related Vulnerabilities
WordPress Plugin WP-Live Chat by 3CX Multiple Vulnerabilities (4.3.5)
Drupal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2020-13674)
WordPress Plugin BestSmallShopLite Cross-Site Scripting (1.0.1)
TYPO3 Improper Input Validation Vulnerability (CVE-2009-0258)
WordPress Plugin Revive Old Post-Auto Post to Social Media Security Bypass (6.9.3)