// For flags

CVE-2021-39333

Hashthemes Demo Importer <= 1.1.1 Improper Access Control Allowing Content Deletion

Severity Score

8.1
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The Hashthemes Demo Importer Plugin <= 1.1.1 for WordPress contained several AJAX functions which relied on a nonce which was visible to all logged-in users for access control, allowing them to execute a function that truncated nearly all database tables and removed the contents of wp-content/uploads.

El plugin Hashthemes Demo Importer para WordPress versiones anteriores a 1.1.1 incluyéndola, contenía varias funciones AJAX que dependían de un nonce que era visible para todos los usuarios conectados para el control de acceso, permitiéndoles ejecutar una función que truncaba casi todas las tablas de la base de datos y eliminaba el contenido de wp-content/uploads

The Hashthemes Demo Importer Plugin for WordPress contained several AJAX functions which relied on a nonce which was visible to all logged-in users for access control in versions up to, and including 1.1.1. This made it possible for authenticated attackers with minimal permissions, such as a subscriber, to execute a function that dropped nearly all a sites database tables and removed the contents of wp-content/uploads.

*Credits: Ramuel Gall, Wordfence
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
None
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-08-20 CVE Reserved
  • 2021-10-26 CVE Published
  • 2024-08-04 CVE Updated
  • 2024-08-04 First Exploit
  • 2024-12-17 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-284: Improper Access Control
  • CWE-862: Missing Authorization
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Hashthemes
Search vendor "Hashthemes"
Hashthemes Demo Importer
Search vendor "Hashthemes" for product "Hashthemes Demo Importer"
<= 1.1.1
Search vendor "Hashthemes" for product "Hashthemes Demo Importer" and version " <= 1.1.1"
wordpress
Affected