CVE-2020-36837
Starter Templates & Sites Pack by ThemeGrill に報告された脆弱性
緊急深刻度
9.9CVSS
1.6.2修正されたバージョン
0.6%30日以内に悪用される確率
概要
The ThemeGrill Demo Importer plugin for WordPress is vulnerable to authentication bypass due to a missing capability check on the reset_wizard_actions function in versions 1.3.4 through 1.6.1. This makes it possible for authenticated attackers to reset the WordPress database. After which, if there is a user named 'admin', the attacker will become automatically logged in as an administrator.
影響を受けるバージョン
- 1.3.4以上 〜 1.6.1以下
対処方法
Starter Templates & Sites Pack by ThemeGrill を 1.6.2 以降に更新してください。これで本脆弱性は解消します。
あなたのサイトは大丈夫ですか?
URLを入力するだけで、実際に使われているプラグインを検出し、 このデータベースと突き合わせて既知の脆弱性が残っていないかを確認できます。登録不要・無料です。
30秒で無料診断する