CVE-2020-36333 affects the themegrill-demo-importer plugin prior to version 1.6.2, allowing unauthenticated attackers to wipe the database due to an insecure reset_wizard_actions hook. This critical vulnerability (CVSS 9.1) has a low attack complexity and can lead to complete data loss (confidentiality, integrity, and availability impacts are high). While not listed on the KEV catalog, public Nuclei templates exist for exploitation, and it has garnered significant community discussion, indicating potential for widespread abuse. There is no evidence of active exploitation or Metasploit modules.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.6.2CPE matchmatch criteria | cpe:2.3:a:themegrill:themegrill_demo_importer:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.