WordPress Plugin Bug Enables Subscribers To Wipe Sites

October 27, 2021

A serious vulnerability in the Hashthemes Demo Importer, a WordPress plugin with more than 8,000 active installations, may allow authenticated attackers to reset and erase target websites.

The Hashthemes Demo Importer plugin is installed to help admins import demos for WordPress themes with a single and no further dependencies.

The security bug enables authenticated attackers to reset WordPress pages and delete almost all database contents and uploaded media.

Ram Gall, Wordfence QA engineer and threat analyst, explained that the plugin could not be properly verified once, causing the AJAX nonce on the admin dashboard of vulnerable websites to leak to all users, “including low privileged users such as subscribers.”

As a result, logged-in subscriber users could exploit the vulnerability to delete all content on websites with unpatched versions of Hashthemes Demo Importer.

While Wordfence reported the bug to the plugin’s development team in August, the developers did not address the vulnerability for the next month.

This prompted Wordfence to contact the WordPress plugins team on September 20, which resulted in the plugin being removed on the same day and a patch being released four days later to fix the bug.

Nevertheless, the developer of the Hashthemes Demo Importer did not announce version 1.1. 2 release or the update on the plugin’s changelog page despite releasing a security update.

For more information, read the original story in BleepingComputer.

Top Stories

Related Articles

April 1, 2026 Anthropic has inadvertently exposed the full source code of its Claude Code tool for the second time more...

April 1, 2026 Cisco suffered a cyberattack after attackers used stolen credentials from a compromised developer tool to access its more...

March 30, 2026 Google has expanded its “Results about you” tool, allowing users to remove highly sensitive personal data, including more...

March 27, 2026 Microsoft is updating GitHub Copilot to train on real-world developer interactions, expanding beyond public code datasets to more...

Picture of TND News Desk

TND News Desk

Staff writer for Tech Newsday.
Picture of TND News Desk

TND News Desk

Staff writer for Tech Newsday.

Jim Love

Jim is an author and podcast host with over 40 years in technology.

Share:
Facebook
Twitter
LinkedIn