A critical flaw found in a WordPress plugin with more than 8,000 installations could allow authenticated attackers to restore and delete vulnerable websites. The WordPress plugin in which the flawis Hashthemes Demo Importer.
See also: Hacker sold data of millions of drivers for $800

This is a plugin designed to help administrators import demos for WordPress themes, without having to deal with installing dependencies.
The bug could allow attackers to reset WordPress sites and delete almost all database content and uploaded media.
Wordfence engineer and threat analyst Ram Gall explained that the WordPress plugin failed to properly perform nonce checks, resulting in the AJAX nonce being leaked to all users in the dashboard of the vulnerable sites. Even low-privileged users and subscribers could access it.
See also: Google: Hackers target YouTubers with cookie theft malware
Consequently, logged-in subscriber-level users could exploit the bug to delete all content on sites running outdated versions of the Hashthemes Demo Importer WordPress plugin.

Subscriber, one of the user types that could delete vulnerable sites, is a default WordPress user role (like Contributor, Author, Editor, and Administrator) that often exists on WordPress sites so that registered users can write comments in the site's comments section.
Normally, subscribers can only edit their profile using the site dashboard and do not have access to other admin pages.
The developers of Hashthemes Demo Importer had been aware of the vulnerability since August 25, 2021, however, they had not responded to Wordfence for at least a month.
See also: How a coding bug turns AirTags into malware distributors
This prompted the researchers to contact the WordPress plugins on September 20, which led to the removal of the plugin the same day and the release of a patch addressing the bug four days later (September 24).
However, the developer of Hashthemes Demo Importer did not mention version 1.1.2 or the update on the plugin's changelog page, despite the release of a security update.
Source: Bleeping Computer
