Description
WordPress Plugin HashThemes Demo Importer is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently completely reset a site, permanently deleting nearly all database content as well as all uploaded media. WordPress Plugin HashThemes Demo Importer version 1.1.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.1.2 or latest
References
Related Vulnerabilities
WordPress Plugin WP Basic Elements Cross-Site Request Forgery (5.2.15)
OpenSSL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-3193)
WordPress Plugin Advanced AJAX Page Loader Cross-Site Request Forgery (2.7.7)
WordPress Plugin Custom 404 Pro Cross-Site Scripting (3.2.7)