WPIntell

Source evidence

ThemeGrill Demo Importer

Starter Templates & Sites Pack by ThemeGrill · support · 2020-02-18T16:44:00+00:00

mixedsentiment
highseverity
0.95relevance
16replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

3 / 25 rows with source links

12.0% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

22 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
mauldincultural resolved
Our website was hacked due to the recent flaw with the ThemeGrill Demo Importer (more info: https://securityaffairs.co/wordpress/98032/hacking/themegrill-demo-importer-wordpress-flaw.html ). All of our pages were deleted and we could not log into our administrative panel. We worked with our site host to successfully retrieve everything, and we updated the theme to 1.6.2, which we believed would fix the issue. However, this morning our site was down again. Our host was able to retrieve it again, but confirmed it was still an issue with our theme (Spacious). We’ve upgraded it to 1.6.3, changed all our passwords, and deleted the admin account, but we deactivated it for fears that this will happen again. Have you all addressed the issue completely, or is this still ongoing? The page I need help with: [ log in to see the link] Hi @mauldincultural , Yes, if you have updated the plugin ‘ThemeGrill Demo Importer’ to 1.6.3, then you should be secure now. Also, as this plugin is used to setup/import the initial demo for ThemeGrill themes, if that purpose is fulfilled, you can simply delete the plugin from your site. If you need it later, you can simply install it. Thanks. Sanjip S. Okay, thank you. I had this same issue, but my host isn’t able to figure out the issue, it seems. I don’t have a wealth of technical skill in this department, so instead my site is just down until I can figure it out. Any idea how I can fix it? Nat The ThemeGrill Demo Importer is NOT listed in my Plugin-List. However, it IS listed in the backend unter “Design/Appearance”. How do I delete it from there?? It’s also found within the foldertree of the theme – can I delete it from there? Please reply ASAP. Thanks! Hi @jbt-csm , Please go to Dashboard > Plugins and you can deactivate and delete the ThemeGrill Demo Importer plugin from the list. Thanks. Hi Ashish, thanks – but as you can read above, I wrote, that it is NOT listed in the list of plugins. BUT it is listed under “ Design/Appearance ”. Maybe that’s because the theme is an older version (Accelerate Pro 2.0.9)? @jbt-csm In that case, it is alright. However, I recommend you to update the theme you’re using to the latest version. Thanks. Hi there, Ashish, Thanks for caring! … ‘alright’ means in this case, that there is no danger that the Demo Importer can be called up or mis-used by hackers? I apprechiate your resonse. This reply was modified 6 years, 3 months ago by jbt-csm . I wanted to add an update to our situation. We deleted the plug-in, but the damage had already been done. Our files were infected with malware, and our host suspended our site until the infected files are cleaned. We’re taking care of the situation, but just wanted to post our experience in case other people go through the same experience and are looking for validation or explanations of what’s going on. I lost all my data due to a security breach, I no longer have a website now ! What will you do ? @anonymouskane – I’m not from ThemeGrill Support (!), but just a quick tip: Usually, your provider keeps regular backups of your WP-database, so you can clean up the system and then try to re-import the data from the backup or your system can be resetted to a point of time before the breach… Hope it helps. I’m gonna try this thanks Found out about this on Ars Technica . I just deleted this plugin as the article recommends. I’m also using Spacious theme. What’s disturbing to me is the fact that the vulnerability has been around for three years. I like the minimalist design of Spacious but I don’t think I could deal with this kind of security threat on my sites. I may know the security basics (which probably saved my site) but still… @jbt-csm , where can I find “Design/Appearance”? I’m not so savvy on the backend side of WordPress. I never knew this plugin should be deleted once it has done its job, or should just be re-installed “on call.” Themegrill, are you considering dropping the demo importer plugin all in all? Why not make Spacious (among others, maybe) available without the need to install the plugin? I came upon this discussion because someone attempted to hack my site with this theme. Gladly my firewall detected it and blocked it and I blocked the IP They did however tried to get to the database to overtake the site. I suggest to install a security plugin and be vigilant of the traffic and have backups of your site to have a clean install should that happen. Believe me I suffered a massive hack 4 years ago.Not fun at all. Thank you for sharing the information. Today, I installed the plugin and the Spacious Store demo. My antivirus immediately notified me that my site was infected. It was only when trying to confirm that it was something to do with ThemeGrill/Spacious that I found this thread about a serious vulnerability that appeared in the demo importer almost a year ago. My antivirus detected that my site tried to make a connection with oops . wpsandbox . io, which is infected with URL:Blacklist. If this is a new issue, then that makes it at least two in 11 months. That suggests that ThemeGrill’s development process is flawed and it is too risky to use their code. Fortunately, my site is new and I can simply delete everything. Unfortunately, this cost me some valuable time. This reply was modified 5 years, 4 months ago by shahmatwu .

Comments

16 shown
ThemeGrill 2020-02-18T16:51:00+00:00

Hi @mauldincultural , Yes, if you have updated the plugin ‘ThemeGrill Demo Importer’ to 1.6.3, then you should be secure now. Also, as this plugin is used to setup/import the initial demo for ThemeGrill themes, if that purpose is fulfilled, you can simply delete the plugin from your site. If you need it later, you can simply install it. Thanks. Sanjip S.

mauldincultural 2020-02-18T17:06:00+00:00

Okay, thank you.

nzorach 2020-02-18T20:26:00+00:00

I had this same issue, but my host isn’t able to figure out the issue, it seems. I don’t have a wealth of technical skill in this department, so instead my site is just down until I can figure it out. Any idea how I can fix it? Nat

jbt-csm 2020-02-19T10:06:00+00:00

The ThemeGrill Demo Importer is NOT listed in my Plugin-List. However, it IS listed in the backend unter “Design/Appearance”. How do I delete it from there?? It’s also found within the foldertree of the theme – can I delete it from there? Please reply ASAP. Thanks!

Ashish – ThemeGrill Support 2020-02-19T11:12:00+00:00

Hi @jbt-csm , Please go to Dashboard > Plugins and you can deactivate and delete the ThemeGrill Demo Importer plugin from the list. Thanks.

jbt-csm 2020-02-19T12:11:00+00:00

Hi Ashish, thanks – but as you can read above, I wrote, that it is NOT listed in the list of plugins. BUT it is listed under “ Design/Appearance ”. Maybe that’s because the theme is an older version (Accelerate Pro 2.0.9)?

Ashish – ThemeGrill Support 2020-02-19T14:00:00+00:00

@jbt-csm In that case, it is alright. However, I recommend you to update the theme you’re using to the latest version. Thanks.

jbt-csm 2020-02-19T14:33:00+00:00

Hi there, Ashish, Thanks for caring! … ‘alright’ means in this case, that there is no danger that the Demo Importer can be called up or mis-used by hackers? I apprechiate your resonse. This reply was modified 6 years, 3 months ago by jbt-csm .

mauldincultural 2020-02-19T15:27:00+00:00

I wanted to add an update to our situation. We deleted the plug-in, but the damage had already been done. Our files were infected with malware, and our host suspended our site until the infected files are cleaned. We’re taking care of the situation, but just wanted to post our experience in case other people go through the same experience and are looking for validation or explanations of what’s going on.

anonymouskane 2020-02-19T16:31:00+00:00

I lost all my data due to a security breach, I no longer have a website now ! What will you do ?

jbt-csm 2020-02-19T16:44:00+00:00

@anonymouskane – I’m not from ThemeGrill Support (!), but just a quick tip: Usually, your provider keeps regular backups of your WP-database, so you can clean up the system and then try to re-import the data from the backup or your system can be resetted to a point of time before the breach… Hope it helps.

anonymouskane 2020-02-19T16:51:00+00:00

I’m gonna try this thanks

flyzilla 2020-02-20T17:13:00+00:00

Found out about this on Ars Technica . I just deleted this plugin as the article recommends. I’m also using Spacious theme. What’s disturbing to me is the fact that the vulnerability has been around for three years. I like the minimalist design of Spacious but I don’t think I could deal with this kind of security threat on my sites. I may know the security basics (which probably saved my site) but still… @jbt-csm , where can I find “Design/Appearance”? I’m not so savvy on the backend side of WordPress. I never knew this plugin should be deleted once it has done its job, or should just be re-installed “on call.” Themegrill, are you considering dropping the demo importer plugin all in all? Why not make Spacious (among others, maybe) available without the need to install the plugin?

teresacuervo 2020-08-11T17:13:00+00:00

I came upon this discussion because someone attempted to hack my site with this theme. Gladly my firewall detected it and blocked it and I blocked the IP They did however tried to get to the database to overtake the site. I suggest to install a security plugin and be vigilant of the traffic and have backups of your site to have a clean install should that happen. Believe me I suffered a massive hack 4 years ago.Not fun at all.

Premi – ThemeGrill Support 2020-08-12T05:51:00+00:00

Thank you for sharing the information.

shahmatwu 2021-01-14T23:19:00+00:00

Today, I installed the plugin and the Spacious Store demo. My antivirus immediately notified me that my site was infected. It was only when trying to confirm that it was something to do with ThemeGrill/Spacious that I found this thread about a serious vulnerability that appeared in the demo importer almost a year ago. My antivirus detected that my site tried to make a connection with oops . wpsandbox . io, which is infected with URL:Blacklist. If this is a new issue, then that makes it at least two in 11 months. That suggests that ThemeGrill’s development process is flawed and it is too risky to use their code. Fortunately, my site is new and I can simply delete everything. Unfortunately, this cost me some valuable time. This reply was modified 5 years, 4 months ago by shahmatwu .