#VU25383 Improper Authentication in ThemeGrill Demo Importer
Published: February 17, 2020
ThemeGrill Demo Importer
ThemeGrill
Description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to the "admin_init hook" runs not only in the admin environment but also on calls to "/wp-admin/admin-ajax.php" which does not require a user to be authenticated. A remote attacker can bypass authentication process and wipe the entire database to its default state after which they are automatically logged in as an administrator.