Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-30789 | The ThemeGrill Demo Importer plugin for WordPress is vulnerable to authentication bypass due to a missing capability check on the reset_wizard_actions function in versions 1.3.4 through 1.6.1. This makes it possible for authenticated attackers to reset the WordPress database. After which, if there is a user named 'admin', the attacker will become automatically logged in as an administrator. |
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 16 Oct 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Themegrill
Themegrill themegrill Demo Importer |
|
| CPEs | cpe:2.3:a:themegrill:themegrill_demo_importer:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Themegrill
Themegrill themegrill Demo Importer |
|
| Metrics |
ssvc
|
Wed, 16 Oct 2024 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The ThemeGrill Demo Importer plugin for WordPress is vulnerable to authentication bypass due to a missing capability check on the reset_wizard_actions function in versions 1.3.4 through 1.6.1. This makes it possible for authenticated attackers to reset the WordPress database. After which, if there is a user named 'admin', the attacker will become automatically logged in as an administrator. | |
| Title | ThemeGrill Demo Importer 1.3.4 - 1.6.1 - Authorization Bypass to Site Reset | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2024-10-16T18:03:47.811Z
Reserved: 2024-10-15T18:39:42.773Z
Link: CVE-2020-36837
Updated: 2024-10-16T17:44:25.200Z
Status : Deferred
Published: 2024-10-16T07:15:08.927
Modified: 2026-04-15T00:35:42.020
Link: CVE-2020-36837
No data.
OpenCVE Enrichment
No data.
EUVD