Bug in WordPress plugin can let hackers wipe up to 200,000 sites.

Updated: May 1, 2023

Same bug can also let attackers gain access to the admin account.

WordPress site owners who use commercial themes provided by ThemeGrill are advised to update one of the plugins that come installed with these themes in order to patch a critical bug that can let attackers wipe their sites.

The vulnerability resides in ThemeGrill Demo Importer, a plugin that ships with themes sold by ThemeGrill, a web development company that sells commercial WordPress themes.

