
WordPress site owners using commercial themes from ThemeGrill are urged to update one of the plugins installed on those themes, as there is a critical vulnerability that could take down their sites.
The vulnerability was found in the ThemeGrill Demo Importer, a plugin that ships with themes from ThemeGrill , a website builder and developer that sells themes for WordPress sites.
The plugin, which is installed on more than 200,000 sites, allows owners to add demos to ThemeGrill themes so they have examples and a starting point to "build" their sites.
However, security firm WebARX stated that older versions of the ThemeGrill Demo Importer contain a vulnerability that makes them vulnerable to remote attacks .

A remote attacker could send a specially crafted payload to the vulnerable sites and trigger a function within the plugin.
This feature could delete all content on vulnerable sites. In short, it could delete all WordPress sites that have a ThemeGrill theme enabled with the vulnerable plugin.
Furthermore, if the site 's database contains a user named "admin", then the hacker gains full administrator access to the site.
According to WebARX researchers, the vulnerability affects all versions of the ThemeGrill Demo Importer plugin, from 1.3.4 to 1.6.1.
ThemeGrill, the company that created the plugin, fixed the bug by releasing the updated version 1.6.2 over the weekend. Owners of vulnerable sites are urged to use the new version to protect their sites.
A month ago, another WordPress plugin was discovered that could delete the content of vulnerable sites. That vulnerability was found in WordPress Database Reset, which was installed on more than 80,000 sites in total.
