Hashthemes Demo Importer
by WordPress
CVEs (2)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-39333 | Hig | 0.53 | 8.1 | 0.01 | Nov 1, 2021 | The Hashthemes Demo Importer Plugin <= 1.1.1 for WordPress contained several AJAX functions which relied on a nonce which was visible to all logged-in users for access control, allowing them to execute a function that truncated nearly all database tables and removed the contents… | ||
| CVE-2026-65483 | Med | 0.00 | 5.9 | 0.00 | Jul 23, 2026 | Author Cross Site Scripting (XSS) in HashThemes Demo Importer <= 1.4.2 versions. |
- risk 0.53cvss 8.1epss 0.01
The Hashthemes Demo Importer Plugin <= 1.1.1 for WordPress contained several AJAX functions which relied on a nonce which was visible to all logged-in users for access control, allowing them to execute a function that truncated nearly all database tables and removed the contents…
- risk 0.00cvss 5.9epss 0.00
Author Cross Site Scripting (XSS) in HashThemes Demo Importer <= 1.4.2 versions.