CVE Feed

    Dashboard / CVE / CVE-2021-39333

    CVE-2021-39333

    The Hashthemes Demo Importer Plugin <= 1.1.1 for WordPress contained several AJAX functions which relied on a nonce which was visible to all logged-in users for access control, allowing them to execute a function that truncated nearly all database tables and removed the contents of wp-content/uploads.

    Published:Nov 1, 2021
    Last Modified:Mar 31, 2025
    EPS:Nov 1, 2021
    EPSS Score:0.00294
    CVSS Score:8.1

    Affected Products

    Vendor
    Hashthemes
    Product
    Hashthemes Demo Importer

    Common Weakness Enumeration

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High