plugin

Wp Reset Vulnerabilities

10 known security issues reported for the Wp Reset WordPress plugin. Most recent disclosed Oct 7, 2025.

2 high 4 medium

Running Wp Reset on your site? Check whether your installed version is affected.

Scan your site free

WP Reset [wp-reset] < 2.06

unknown

[en] The WP Reset plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.05 via the WF_Licensing::log() method when debugging is enabled (default). This makes it possible for unauthenticated attackers to extract sensitive license key and site data.

Affected:
up to 2.06
Fixed in:
2.06
Disclosed:
Oct 7, 2025

CVE-2025-10645 on NVD →

WP Reset <= 2.05 - Unauthenticated Sensitive Information Exposure via wf-licensing.log

medium

The WP Reset plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.05 via the WF_Licensing::log() method when debugging is enabled (default). This makes it possible for unauthenticated attackers to extract sensitive license key and site data.

CVSS:
5.3
Affected:
up to 2.05
Fixed in:
2.06
Disclosed:
Oct 6, 2025

CVE-2025-10645 on NVD →

WP Reset [wp-reset] < 2.03

unknown

[en] The WP Reset plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_ajax function in all versions up to, and including, 2.02. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify the value fo the 'Licens...

Affected:
up to 2.03
Fixed in:
2.03
Disclosed:
Jun 8, 2024

CVE-2024-4661 on NVD →

WP Reset <= 2.02 - Missing Authorization to License Key Modification

medium

The WP Reset plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_ajax function in all versions up to, and including, 2.02. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify the value fo the 'License Key...

CVSS:
4.3
Affected:
up to 2.01
Fixed in:
2.03
Disclosed:
Jun 7, 2024

CVE-2024-4661 on NVD →

WP Reset [wp-reset] < 2.0

unknown

[en] The WP Reset – Most Advanced WordPress Reset Tool plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0 via the use of insufficiently random snapshot names. This makes it possible for unauthenticated attackers to extract sensitive data including site backups...

Affected:
up to 2.0
Fixed in:
2.0
Disclosed:
Apr 9, 2024

CVE-2023-6799 on NVD →

WP Reset <= 2.0 - Sensitive Information Exposure due to Insufficient Randomness

medium

The WP Reset – Most Advanced WordPress Reset Tool plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0 via the use of insufficiently random snapshot names. This makes it possible for unauthenticated attackers to extract sensitive data including site backups by b...

CVSS:
5.9
Affected:
up to 2.0
Fixed in:
2.01
Disclosed:
Mar 26, 2024

CVE-2023-6799 on NVD →

WP Reset PRO 5.00-5.98 - Cross-Site Request Forgery

high

Cross-Site Request Forgery (CSRF) vulnerability leading to Database Reset in WordPress WP Reset PRO Premium plugin (versions <= 5.98) allows attackers to trick authenticated into making unintentional database reset.

CVSS:
8.8
Affected:
5.00 – 5.98
Fixed in:
5.99
Disclosed:
Nov 10, 2021

CVE-2021-36908 on NVD →

WP Reset – Most Advanced WordPress Reset Tool (PRO) 5.00- 5.98 - Missing Authorization to Database Reset

high

Authenticated Database Reset vulnerability in WordPress WP Reset PRO Premium plugin (versions <= 5.98) allows any authenticated user to wipe the entire database regardless of their authorization. It leads to a complete website reset and takeover.

CVSS:
8.8
Affected:
5.00 – 5.98
Fixed in:
5.99
Disclosed:
Nov 10, 2021

CVE-2021-36909 on NVD →

WP Reset [wp-reset] < 1.90

unknown

[en] The WP Reset – Most Advanced WordPress Reset Tool WordPress plugin before 1.90 did not sanitise or escape its extra_data parameter when creating a snapshot via the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue

Affected:
up to 1.90
Fixed in:
1.90
Disclosed:
Jul 12, 2021

CVE-2021-24424 on NVD →

WP Reset <= 1.86 - Authenticated Stored Cross-Site Scripting via extra_data Parameter

medium

The WP Reset – Most Advanced WordPress Reset Tool WordPress plugin before 1.90 did not sanitise or escape its extra_data parameter when creating a snapshot via the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue

CVSS:
5.5
Affected:
up to 1.86
Fixed in:
1.90
Disclosed:
May 26, 2021

CVE-2021-24424 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database