Learn how we count contributions. Description. Moreover, be careful about the plugins you choose. October 27, 2021; WordPress Plugin Bug Lets Subscribers Wipe Sites This post was originally published on this site. A you a WordPress user? The flaw enables any authorized user to entirely wipe a susceptible site clean, erasing all of the material and data posted to it. Fix The CVE-2021-42367 Vulnerability- A XSS Vulnerability ... This plugin works for theme developed by SparleThemes and if other themes wants to use then they have to use action filter to work.. You just need to define the array that includes the location of the demo zip files and other related info. Less More 2021; 2020; 2019; 2018; 2017; 2016; 2015 . This security bug allows an attacker to reset a WordPress site and delete almost all database content and uploaded media. hashthemes demo importer vulnerabilities and exploits The Hashthemes demo importer plugin failed to perform capability checks for many of its AJAX actions. It is specially developed to add a demo importer functionality in the theme developed by HashThemes but it can also be used by any other themes as well. CVE.report - indeed-job-importer This plugin works for theme developed by SparleThemes and if other themes wants to use then they have to use action filter to work. HashThemes Demo Importer imports the full demo with just one click. The Hashthemes Demo Importer and is found in more than 8,000 blogs, according to researchers at Wordfence. WordPress plugin bug can lead to complete loss of site ... Site Deletion Vulnerability in Hashthemes Plugin - WP Guy News It is specially developed for demo import purpose. This vulnerability allowed any authenticated user to completely reset a site, permanently deleting nearly all database content as well as all uploaded media. Unless backed up, the bug could see the website unrecoverable, one expert has said Credit: Getty. The security bug would allow authenticated attackers to reset WordPress sites and delete almost all database content and uploaded media. View Analysis Description Description Sparkle Demo Importer imports sparkle themes full demo with just one click. On August 25, 2021, the Wordfence Threat Intelligence team initiated the disclosure process for a vulnerability in Hashthemes Demo Importer, a WordPress plugin with over 7,000 installations. 8.1 - HIGH: 2021-11-01 2021-11-17 CVE-2021-39317: Versions up to, and including, 1.0.6, of the Access Demo Importer WordPress plugin are vulnerable to arbitrary file uploads v. 8.8 - HIGH: 2021-10-11 2021-10-11 Description Sparkle Demo Importer imports sparkle themes full demo with just one click. Get detail documentation with 24x7 support. The bottom line. The Hashthemes Demo Importer Plugin <= 1.1.1 for WordPress contained several AJAX functions which relied on a nonce which was visible to all logged-in users for access control, allowing them to execute a function that truncated nearly all database tables and removed the. HashThemes Demo Importer. Read More. This vulnerability allowed any authenticated user to completely reset a site, permanently deleting nearly all database content as well as all uploaded media. While it did perform a nonce check, the AJAX nonce was visible in the admin dashboard for all users, including low-privileged users such as subscribers. Cybercriminals leveraging the SolarMarker .NET-based backdoor are using a technique called SEO poisoning to drive malicious payloads into victims' systems so they . Source: Threatpost. The HashThemes Demo Importer plugin is designed to let admins easily import demos for WordPress themes with a single click, without having to deal with dependencies such as XML files, .json theme. The security. CVE-2021-39333. In October, a high severity bug was found in the Hashthemes Demo Importer WordPress plugin, which could enable attackers to reset and wipe vulnerable sites. It is specially developed for demo import purpose. Description. Start building your own website in no time. A new version 1.1.2 of the plugin has been put up, although no changenotes have been published. High Severity . HashThemes - Free & Premium WordPress Themes, Templates & Plugins Store Viral Pro A Premium Magazine WordPress Theme One Click Demo Importer with 14+ Demos Elementor & Customzer Ready 50+ News/Magazine Block Styles 20+ Custom Built Widgets for Magazine Website Multiple Stylish Archive Layouts Multiple Stylish Post Layouts Multiple Header Styles CVE-2021-39333 Vulnerability details Plugin changelog. A high severity security flaw found in a WordPress plugin with more than 8,000 active installs can let authenticated attackers reset and wipe vulnerable websites. This plugin works for theme developed by SparleThemes and if other themes wants to use then they have to use action filter to work.. You just need to define the array that includes the location of the demo zip files and other related info. For instance, in October researchers discovered a high-severity vulnerability in the Hashthemes Demo Importer plugin that allows subscribers to wipe sites clean of content. This plugin works for theme developed by SparleThemes and if other themes wants to use then they have to use action filter to work. The plugin in question, known as Hashthemes Demo Importer, is designed to help admins import demos for WordPress themes with a single, without dealing with installing any dependencies. The plugin, HashThemes Demo Importer, has a vulnerability (rated 8.1 on the CVSS scale) that, when exploited, can cause a full reset of a WordPress site.This effectively would wipe any trace of prior data on a WordPress webpage, regardless if it is written word or forms of media. They can do this with a single click without dealing with dependencies such as XML files, .json theme options, .dat customizer files, or .wie widget files. The Hashthemes demo importer plugin failed to perform capability checks for many of its AJAX actions. This plugin is used by thousands of websites and can let authenticated attackers reset and wipe vulnerable websites. Registrations for The Events Calendar . And, in November 2021. another WordPress plugin in lets attackers display a fake ransomware encryption message demanding about $6,000 to unlock the site. Sparkle Demo Importer imports sparkle themes full demo with just one click. Total - Total Plus Demo. HashThemes Demo Importer Web applications / Modules and components for CMS. WP-Pro-Quiz 32. No entanto, o desenvolvedor do Hashthemes Demo Importer não mencionou a versão 1.1.2 ou a atualização na página do changelog do plugin, apesar de lançar uma atualização de segurança. This vulnerability allowed any authenticated user to completely reset a site, permanently deleting nearly all database content as well as all uploaded media. Πηγή: Bleeping Computer Jeff Burt. AN URGENT warning has been issued to WordPress users after a bug on the system reportedly allowed hackers to delete entire sites. Discovered by Wordpress security experts Wordfence, the vulnerability exists in the Hashthemes Demo Importer plugins that boasts of more than 8,000 active installs, and is designed to help admins . 123 contributions in the last year Sep Oct Nov Dec Jan Feb Mar Apr May Jun Jul Aug Sep Sun Mon Tue Wed Thu Fri Sat. CVE-CVE-2021-39333 References. This vulnerability allowed any authenticated user […] Registrations for The Events Calendar 27. Sparkle Demo Importer imports sparkle themes full demo with just one click. Ramuel Gall (WordFence) Classification. The Hashthemes Demo Importer Plugin <= 1.1.1 for WordPress contained several AJAX functions which relied on a nonce which was visible to all logged-in users for access control, allowing them to execute a function that truncated nearly all database tables and removed the contents of wp-content/uploads. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently completely reset a site, permanently deleting nearly all database content as well as all uploaded media. HashThemes Demo Importer. This plugin, called Hashthemes Demo Importer, is designed to allow administrators to import WordPress theme demos without the need to install any dependency software. Timeline. eCommerce Product Catalog Plugin for WordPress. The security flaw was first noted by Wordfence who said it it affected the Hashthemes Demo Importer plugin. Discovered by Researchers at Wordfence, the vulnerability exists in the Hashthemes Demo Importer plugins that has more than 8,000 active installs, and is designed to help admins import demos for . You just need to define the array that includes the location of the demo zip files and other informations. Vulnerability CVE-2021-39333. Contact Form by Supsystic 33. While it did perform a nonce check, the AJAX nonce was visible in the admin dashboard for all users, including low-privileged users such as subscribers. The Hash Themes Demo Importer plugin is designed to allow admins to quickly and easily import demos for WordPress themes. While it did perform a nonce check, the AJAX nonce was visible in the admin dashboard for all users, including low-privileged users such as subscribers. The vulnerability exists due to improper access restrictions. Detailed Documentation. A new flaw has been discovered in a popular WordPress plugin called Hashthemes Demo Importer. The HashThemes Demo Importer plugin is designed to let admins easily import demos for WordPress themes with a single click. The Hashthemes Demo Importer Plugin <= 1.1.1 for WordPress contained several AJAX functions which relied on a nonce which was visible to all logged-in users for access control, allowing them to execute a function that truncated nearly all database tables and removed the contents of wp-content/uploads. It also has no dependencies such as XML files, .json theme options, .dat customizer files or .wie widget files. Ωστόσο, ο προγραμματιστής του Hashthemes Demo Importer δεν ανέφερε την έκδοση 1.1.2 ή το update στη σελίδα καταγραφής αλλαγών του plugin, παρά την κυκλοφορία μιας ενημέρωσης ασφαλείας. For more such updates follow us on Google News ITsecuritywire News The flaw, found in the Hashthemes Demo Importer plugin, allows any authenticated user to exsanguinate a vulnerable WordPress site, deleting nearly all database content and uploaded media. Import the fully function demo with just single click. Once the plugin is installed, you will land on the HashThemes Demo Importer page where you can find all the demos are available. The HashThemes Demo Importer plugin is designed to let admins easily import demos for WordPress themes with a single click, without having to deal with dependencies such as XML files, .json theme options,.dat customizer files or .wie widget files. Discovered by Wordpress security experts Wordfence, the vulnerability exists in the Hashthemes Demo Importer plugins that boasts of more than 8,000 active installs, and is designed to help admins . Description. Cyber Espionage, North Korea's APT37 spread Chinotto to monitor opponents. The most severe consequence of this was that a subscriber-level user could reset all of the . Source: Bleeping Computer Follow us on Google News and be the first to know about all the news. The Hashthemes Demo Importer vulnerability permits site wipes and was discovered in late August, 2021. The Hashthemes Demo Importer Plugin = 1.1.1 for WordPress contained several AJAX functions which relied on a nonce which was. นอกจากนี้มีรายงานว่ายังพบว่ามีปลั๊กอิน Wordpress อีกหลายตัวที่ถูกดัดแปลงด้วย คือ WP Reset Pro, OptinMonster, Hashthemes Demo Importer ซึ่งการแก้ไขที่ง่ายที่สุด . Click on the "Preview" button to get a quick view of the demo and install button to start the demo installation. The vulnerability is patched, so you should update to version 1.1.2. In October 2021, a WordPress plugin bug was discovered in the Hashthemes Demo Importer plugin, that allowed users with simple subscriber permissions to wipe all content. September 27, . Discovered by Wordpress security experts Wordfence, the vulnerability exists in the Hashthemes Demo Importer plugins that boasts of more than 8,000 active installs, and is designed to help admins import demos for WordPress themes with a single click. This WordPress plugin is designed to import demo content from HashThemes.com. The HashThemes Demo Importer plugin is designed to let admins easily import demos for WordPress themes with a single click, without having to deal with dependencies such as XML files, .json theme options,.dat customizer files or .wie widget files. Wordfence cybersecurity experts: The plugin flaw enables any authorized user to entirely wipe a site clean, erasing all of the material and data posted to it. Update the WordPress HashThemes Demo Importer plugin to the latest available version (at least 1.1.2). NextScripts: Social Networks Auto-Poster 30. The plugin in question, known as Hashthemes Demo Importer, is designed to help admins import demos for WordPress themes with a single, without dealing with installing any dependencies. The Hashthemes Demo Importer Plugin <= 1.1.1 for WordPress contained several AJAX functions which relied on a nonce which was visible to all logged-in users for access control, allowing them to execute a function that truncated nearly all database tables and removed the. Hashthemes, a WordPress plugin with 8,000 active installations, allowed hackers to completely reset a site, deleting almost all the content from . Note: To receive disclosures like this in your inbox the moment they're published, you can subscribe to our WordPress Security Mailing List. Timeline. It lets you import a fully functioning website with just one click or with a few steps. WordPress, Hashthemes Demo Importer has a critical vulnerability. OWASP Top 10. Just select the demo and click Install. 1. The Hashthemes Demo Importer plugin is installed to help admins import demos for WordPress themes with a single and no further dependencies. The most severe consequence of this was that a subscriber-level user could reset all of the . OptinMonster 29. However, it's possible for subscribers to use … High Severity 8.1 Improper Access Control allowing content deletion vulnerability. One Click Demo Installation Import the demo contents including pages, posts, sliders, widgets, theme options and other settings with only one click. The plugin boasts more than 8,000 active installations. Fuente: https://www.bleepingcomputer.com The plugin in question, known as Hashthemes Demo Importer, is designed to help admins import demos for WordPress themes with a single, without dealing with installing any dependencies. In a Tuesday writeup, Wordfence's Ram Gall said that the Wordfence Threat Intelligence team . Automatic Updates Get Hasle free updates with Square Plus. Siga canalfsociety em Instagram, Facebook, . If so, you need to be aware of a security flaw found in the Hashthemes Demo Importer plugin. n August 25, 2021, the Wordfence Threat Intelligence team initiated the disclosure process for a vulnerability in Hashthemes Demo Importer, a WordPress plugin with over 7,000 installations. Smash Balloon Social Post Feed 31. The HashThemes Demo Importer plugin allows you to easily import demos for WordPress themes with a single click. The Hashthemes Demo Importer Plugin <= 1.1.1 for WordPress contained several AJAX functions which relied on a nonce which was visible to all logged-in users for access control, allowing them to execute a function that truncated nearly all database tables and removed the contents of wp-content/uploads. The issue identified was that the Hashthemes demo importer plugin hadn't performed capability . Premium WordPress Theme. Read More. Discovered by WordPress security experts Wordfence, the vulnerability exists in the Hashthemes Demo Importer plugins that boast of more than 7,000 active installs, according to Wordffence researchers, and is designed to help administrators import demos for WordPress themes with a single click. The vulnerability alert came to our attention via our security team who have already notified the developer about it (as well as other development agencies . Sin embargo, el desarrollador de Hashthemes Demo Importer no mencionó la versión 1.1.2 o la actualización en la página de registro de cambios del complemento a pesar de haber lanzado una actualización de seguridad. Hashthemes Demo Importer is a popular WordPress plugin, but it has a critical vulnerability. Researchers at Wordfence warned of a vulnerability (CVE-2021-39333) affecting a known WordPress plugin. Vendor: Hash Themes. September 27, . Note: To receive disclosures like this in your inbox the moment they're published, you can subscribe to our WordPress Security Mailing List. A remote authenticated attacker can execute a function that . The high-severity security flaw is found in Hashthemes Demo Importer, a plugin that is used in more than 8,000 active installations. The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality. The Hashthemes demo importer plugin failed to perform capability checks for many of its AJAX actions. It has been discovered by Wordfence cybersecurity experts. By doing so, you can save a lot of time that would be consumed if you start building your website from scratch. October 29, 2021. One Click Demo Importer PHP. Credits. The most severe consequence of this was that a subscriber-level user could reset all of the . It's a high-severity security flaw. WordPress Plugin HashThemes Demo Importer is prone to a security bypass vulnerability. According to Wordfence's QA engineer and threat . This vulnerability allowed any authenticated user […] You just need to define the array that includes the location of the demo zip files and other informations. One Click Demo Importer. eCommerce Product Catalog is a free product catalog plugin for WordPress eCommerce or a simple product catalog website with a request for a quote functionality. Vulnerable Versions <= 1.1.1 Fixed in version. A5: Broken Access Control . The flaw, found in the Hashthemes Demo Importer plugin, allows any authenticated user to damage a vulnerable WordPress site, deleting nearly all database content & uploaded media. As with the recently disclosed site deletion vulnerability in HashThemes Demo Importer, this vulnerability stresses the importance of maintaining regular back-ups so in the event that information goes missing on a site, it can easily be restored. It is specially developed to add a demo importer functionality in the theme developed by HashThemes but it can also be used by any other themes as well. A security researcher named Ram Gall from Wordfence said that he reported the bug to the developer of the plug-in on Aug. 25. It is specially developed for demo import purpose. HashThemes Demo Importer. On August 25, 2021, the Wordfence Threat Intelligence team initiated the disclosure process for a vulnerability in Hashthemes Demo Importer, a WordPress plugin with over 7,000 installations. Discovered by WordPress security experts Wordfence, the vulnerability exists in the Hashthemes Demo Importer plugins that boast of more than 7,000 active installs, according to Wordffence researchers, and is designed to help administrators import demos for WordPress themes with a single click. Mang Board WP 28. On August 25, 2021, the Wordfence Threat Intelligence team initiated the disclosure process for a vulnerability in Hashthemes Demo Importer, a WordPress plugin with over 7,000 installations. Keep an eye out for updates and software patches, while using popular CMS platforms. However, the developer of Hashthemes Demo Importer did not mention version 1.1.2 or the update on the plugin change log, despite the release of a security update. hashthemes-demo-importer Public. The Hashthemes Demo Importer plugin allows WordPress admins to import demos for WordPress themes with a single click without having to bother installing any dependencies such as XML files and .wie widget files. 26. Achou esse artigo interessante? HashThemes Demo Importer 26. It is specially developed for demo import purpose. HashThemes Demo Importer imports the full demo with just one click. The vulnerability allows any authenticated user to wipe a vulnerable WordPress site completely clean, deleting all content and uploaded media. On August 25, 2021, the Wordfence Threat Intelligence team initiated the disclosure process for a vulnerability in Hashthemes Demo Importer, a WordPress plugin with over 7,000 installations. As with the recently disclosed site deletion vulnerability in HashThemes Demo Importer, this vulnerability stresses the importance of maintaining regular back-ups so in the event that information goes missing on a site, it can easily be restored. 1.1.2. The plugin has been installed on approximately 8,000 WordPress sites. Arbitrary Content Deletion. Descripción. It's that easy as that! The security bug enables authenticated attackers to . Plugin: HashThemes Demo Importer Vulnerability: Improper Access Control to Blog Reset Patched in Version: 1.1.2 Severity Score: Critical. CVE. Demo Import is one of the most trending features for WordPress Themes. Hadn & # x27 ; s a high-severity security flaw found in plugin that can WordPress. Ram Gall from Wordfence said that the Wordfence Threat Intelligence team have to use action filter to.... Filter to work: //www.cybersecurity-help.cz/vulnerabilities/58264/ '' > WordPress HashThemes Demo Importer plugin most severe of... ; 2015 to monitor opponents the full Demo with just one click with Square Plus, Korea... Files and other informations reset a site, deleting almost all database content well. Content and uploaded media would be consumed if you start building your website from scratch to!.Dat customizer files or.wie widget files monitor opponents on Aug. 25, erasing all of Demo. Files and other informations put up, the bug could see the website unrecoverable, expert! Let authenticated attackers reset and wipe vulnerable websites deleting almost all database content as as! Wipe... < /a > HashThemes Demo Importer is prone to a security flaw is in. The vulnerability is Patched, so you should update to version 1.1.2:...: //www.cybersecurity-help.cz/vulnerabilities/58264/ '' > WordPress HashThemes Demo Importer < /a > HashThemes Demo Importer - WordPress plugin bug subscribers! '' hashthemes demo importer: //www.cybernewsgroup.co.uk/wordpress-plugin-bug-allows-subscribers-to-wipe-sites/ '' > Brutal WordPress plugin bug allows subscribers to...... Remote attacker to gain unauthorized Access to otherwise restricted functionality: 1.1.2 Severity Score: Critical: ''. The HashThemes Demo Importer imports sparkle themes full Demo with just one click updates... 1.1.2 Severity Score: Critical, while using popular CMS platforms then they have use... S Ram Gall said that the Wordfence Threat Intelligence team import Process Failed bug found in the HashThemes Importer! > sparkle Demo Importer WordPress plugin vulnerability... < /a > HashThemes Demo is. He reported the bug could see the website unrecoverable, one expert said... Said that the HashThemes Demo Importer plugin & lt ; = 1.1.1... < >! Access to otherwise restricted functionality sites... < /a > HashThemes Demo Importer < /a HashThemes! To completely reset a site, permanently deleting nearly all database content and uploaded media in Demo! Is prone to a security flaw was first noted by Wordfence who said it it affected the HashThemes Demo plugin! Careful about the plugins you choose Wordfence Threat Intelligence team the array that includes the of... > Improper Access Control to Blog reset Patched in version: 1.1.2 Score! Content as well as all uploaded media us on Google News and be the first to about!: //patchstack.com/database/vulnerability/hashthemes-demo-importer/wordpress-hashthemes-demo-importer-plugin-1-1-1-improper-access-control-allowing-content-deletion-vulnerability '' > WordPress HashThemes Demo Importer plugin clean, deleting all content uploaded. To import Demo content from import Demo content from HashThemes.com function that & # x27 ; t performed.... > Demo import Process Failed News and be the first to know about all the content from HashThemes.com about. & lt ; = 1.1.1 Fixed in version: HashThemes Demo Importer WordPress plugin bug allows subscribers to wipe <... Plugin vulnerability... < /a > hashthemes-demo-importer Public security bypass vulnerability ; 2017 ; 2016 ; 2015 using! Severity Score: Critical, you can save a lot of time that would be consumed if start! Http: //www.cybernewsgroup.co.uk/wordpress-plugin-bug-allows-subscribers-to-wipe-sites/ '' > WordPress plugin bug allows subscribers to wipe sites... < /a > hashthemes-demo-importer.! Expert has said Credit: Getty Importer is prone to a security bypass vulnerability //patrickdomingues.com/2021/10/28/hashthemes-demo-importer-wordpress-plugin-vulnerability/ '' > Improper hashthemes demo importer to... Files and other informations that includes the location of the s a high-severity security flaw found in that! It lets you import a fully functioning website with just one click Wordfence said that the HashThemes Demo Importer:. A Tuesday writeup, Wordfence & # x27 ; s a high-severity security flaw attackers to reset site. Of this was that a subscriber-level user could reset all of the plug-in on Aug. 25 Follow on! New version 1.1.2 of the Blog reset Patched in version: 1.1.2 Severity Score: Critical < >. New version 1.1.2 Access Control allowing content deletion vulnerability no changenotes have been published gain unauthorized Access otherwise... Use then they have to use then they have to use action filter to.. Prone to a security flaw found in plugin that can erase WordPress and! Is used by thousands of websites and can let authenticated attackers to reset a,. By SparleThemes and if other themes wants to use then they have to use then they have use! Importer plugin & lt ; = 1.1.1... < /a > HashThemes Demo Importer plugin & lt ; =.... As well hashthemes demo importer all uploaded media have to use action filter to.! Source: Bleeping Computer Follow us on Google hashthemes demo importer and be the to... Deletion vulnerability 2016 ; 2015 all of the material and data posted to it could reset all of Demo... And Threat websites and can let authenticated attackers to reset WordPress sites s Ram Gall said that the Wordfence Intelligence... The Demo zip files and other informations they have to use then they have to use action filter work. Sparkle themes full Demo with just one click the issue identified was that the Wordfence Threat Intelligence team used! Cc < /a > hashthemes-demo-importer Public # x27 ; s Ram Gall from Wordfence said the! Other informations to work site clean, deleting all content and uploaded media,.dat customizer or... You just need to define the array that includes the location of the plugin been! Deleting nearly all database content and uploaded media s a high-severity security flaw found the. Flaw enables any authorized user to wipe sites... < /a > update the WordPress HashThemes Demo Importer - plugin! Writeup, Wordfence & # x27 ; s Ram Gall said that reported... Demo content from HashThemes.com and wipe vulnerable websites deletion vulnerability from Wordfence said that he reported the bug could the... Has said Credit: Getty sparkle themes full Demo with just one click or with a few steps allows... S Ram Gall from Wordfence said that he reported the bug to the developer of Demo. Wordfence Threat Intelligence team one expert has said Credit: Getty, while popular! Named Ram Gall from Wordfence said that the HashThemes Demo Importer < /a >.... 8,000 active installations that includes the location of the plug-in on Aug. 25 Importer, a plugin that is by. Plugin works for theme developed by SparleThemes and if other themes wants to use then they to! Researcher named Ram Gall said that he reported the bug to the developer of the plugin hadn & # ;!: Critical the full Demo with just one click the website unrecoverable, one expert has Credit. Entirely wipe a vulnerable WordPress site completely clean, erasing all of hashthemes demo importer on. Us on Google News and be the first to know about all the content from to reset sites! For updates and software patches, while using popular CMS platforms monitor opponents Importer WordPress. Import a fully functioning website with just one click all content and uploaded media at 1.1.2. Themes full Demo with just one click or with a few steps authenticated... A subscriber-level user could reset all of the issue identified was that HashThemes... A new version 1.1.2 of the Demo zip files and other informations all! Works for theme developed by SparleThemes and if other themes wants to use action to. Bug would allow authenticated attackers reset and wipe vulnerable websites approximately 8,000 WordPress sites # x27 s... Has been installed on approximately 8,000 WordPress sites the plugin has been installed on 8,000... Would be consumed if you start building your website from scratch entirely wipe a susceptible site clean, deleting content. He reported the bug could see the website unrecoverable, one expert has said Credit: Getty website!: Getty import Process Failed 2017 ; 2016 ; 2015 a plugin is. A fully functioning website with just single click ; = 1.1.1... < /a > Description content as as. To be aware of a security researcher named Ram Gall from Wordfence said that the HashThemes Demo Importer imports themes! T performed capability a subscriber-level user could reset all of the options,.dat customizer or! User to wipe sites... < /a > Description 1.1.1... < >... Reset all of the Demo zip files and other informations Severity 8.1 Improper Access Control Blog. Us on Google News and be the first to know about all the content from.! First to know about all the News an eye out for updates and patches! Affected the HashThemes Demo Importer should update to version 1.1.2 researcher named Ram Gall said that Wordfence... Brutal WordPress plugin bug allows an attacker to reset WordPress sites Access to otherwise restricted functionality WordPress.org a you a WordPress user popular CMS platforms know about all the.... Control to Blog reset Patched in version: 1.1.2 Severity Score: Critical bug allows an attacker reset. You need to define the array that includes the location of the Demo zip files and other informations security named... Wordpress sites as that files and other informations zip files and other informations is to. This plugin works for theme developed by SparleThemes and if other themes to! To use action filter to work or with a few steps,.dat customizer files or widget... Just need to be aware of a security bypass vulnerability the Wordfence Threat Intelligence team > bug found the. And Threat monitor opponents to reset WordPress sites and delete almost all database content as well as all media... - PRSOL: CC < /a > HashThemes Demo Importer is prone to a security found. Flaw is found in HashThemes Demo Importer plugin & lt ; = Fixed! Function that 1.1.2 of the has said Credit: Getty a href= '' https: //www.prsol.cc/bug-found-in-plugin-that-can-erase-wordpress-sites/ '' WordPress! Site clean, deleting all content and uploaded media a you a WordPress?.