Database Reset <= 3.22 - Cross-Site Request Forgery to WP Reset Plugin Installation
medium
The Database Reset plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.22. This is due to missing or incorrect nonce validation on the install_wpr() function. This makes it possible for unauthenticated attackers to install the WP Reset Plugin via a forged request gra...
- CVSS:
- 4.7
- Affected:
- up to 3.22
- Fixed in:
- 3.23
- Disclosed:
- Feb 20, 2024
CVE-2024-1501 on NVD →
WP Database Reset <= 3.1 - Privilege Escalation
critical
The WordPress plugin, WP Database Reset through 3.1, contains a flaw that gave any authenticated user, with minimal permissions, the ability (with a simple wp-admin/admin.php?db-reset-tables[]=users request) to escalate their privileges to administrator while dropping all other users from the table.
- CVSS:
- 9.9
- Affected:
- up to 3.1
- Fixed in:
- 3.15
- Disclosed:
- Jan 16, 2020
CVE-2020-7047 on NVD →
WP Database Reset <= 3.1 - Unauthenticated Database Reset
critical
The WordPress plugin, WP Database Reset through 3.1, contains a flaw that allowed any unauthenticated user to reset any table in the database to the initial WordPress set-up state (deleting all site content stored in that table), as demonstrated by a wp-admin/admin-post.php?db-reset-tables[]=comments URI.
- CVSS:
- 9.1
- Affected:
- up to 3.1
- Fixed in:
- 3.15
- Disclosed:
- Jan 16, 2020
CVE-2020-7048 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database