All thanks to the free plugin called “ThemeGrill Demo Importer” which imports ThemeGrill themes with one click.
There is an error in the plug-in code that allows the plug-in to perform some operations with administrator privileges and verification is bypassed. This means that any user on the site with this plugin can perform administrator operations. The whole action is that this flaw may eventually allow unauthenticated remote attackers to clean the entire database of target websites to their default state, after which they will be automatically logged in as an administrator, which in turn will allow them to take full control of the website and its subpages.
The scale of the problem can be large, because if you believe the WordPress statistics, the plugin was installed over 100,000 times (and according to other sources over 200,000 times)