CVE-2021-39333
Hashthemes Demo Importer <= 1.1.1 Improper Access Control Allowing Content Deletion
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The Hashthemes Demo Importer Plugin <= 1.1.1 for WordPress contained several AJAX functions which relied on a nonce which was visible to all logged-in users for access control, allowing them to execute a function that truncated nearly all database tables and removed the contents of wp-content/uploads.
El plugin Hashthemes Demo Importer para WordPress versiones anteriores a 1.1.1 incluyéndola, contenía varias funciones AJAX que dependían de un nonce que era visible para todos los usuarios conectados para el control de acceso, permitiéndoles ejecutar una función que truncaba casi todas las tablas de la base de datos y eliminaba el contenido de wp-content/uploads
The Hashthemes Demo Importer Plugin for WordPress contained several AJAX functions which relied on a nonce which was visible to all logged-in users for access control in versions up to, and including 1.1.1. This made it possible for authenticated attackers with minimal permissions, such as a subscriber, to execute a function that dropped nearly all a sites database tables and removed the contents of wp-content/uploads.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-08-20 CVE Reserved
- 2021-10-26 CVE Published
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-284: Improper Access Control
- CWE-862: Missing Authorization
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://www.wordfence.com/blog/2021/10/site-deletion-vulnerability-in-hashthemes-plugin | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Hashthemes Search vendor "Hashthemes" | Hashthemes Demo Importer Search vendor "Hashthemes" for product "Hashthemes Demo Importer" | <= 1.1.1 Search vendor "Hashthemes" for product "Hashthemes Demo Importer" and version " <= 1.1.1" | wordpress |
Affected
|