📦

hashthemes_demo_importer

Vendor: hashthemes

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 0 Remote Access
Total CVEs 1 Total Indexed
Avg. EPSS 1.02% Exploit Prob.
Latest CVE CVE-2021-39333 Nov 01

Security Vulnerability Index

Page 1 / 1
8.1 CVSS

The Hashthemes Demo Importer Plugin <= 1.1.1 for WordPress contained several AJAX functions which relied on a nonce which was visible to all logged-in users for access control, allowing them to execute a function that truncated nearly all database tables and removed the contents of wp-content/uploads.

EPSS: 1.02%