CVE-2020-36333: Themegrill Demo Importer

Critical severity, CVSS 9.1. EPSS: 4.1% chance of exploitation in the next 30 days.

themegrill-demo-importer before 1.6.2 does not require authentication for wiping the database, because of a reset_wizard_actions hook.

Affected products

  • Themegrill Themegrill Demo Importer: before 1.6.2 (fixed in 1.6.2)

Published 2021-05-05. Last modified 2026-06-17.