Description
WordPress Plugin HashThemes Demo Importer is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently completely reset a site, permanently deleting nearly all database content as well as all uploaded media. WordPress Plugin HashThemes Demo Importer version 1.1.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.1.2 or latest
References
Related Vulnerabilities
WordPress Plugin eBay Feeds for WordPress Cross-Site Scripting (1.0)
WordPress Plugin FG PrestaShop to WooCommerce Cross-Site Scripting (3.19.1)
WordPress Plugin eHive Account Details Cross-Site Scripting (2.1.2)
WordPress Plugin WordPress Clean Up & Optimizer-Clean Up Optimizer SQL Injection (3.0.13)