CVEs (3)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The Database Reset plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.22. This is due to missing or incorrect nonce validation on the install_wpr() function. This mak...Show more |
1Webfactoryltd 1Wp Database Reset Nov 21, 2024 Jan 16, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 The WordPress plugin, WP Database Reset through 3.1, contains a flaw that allowed any unauthenticated user to reset any table in the database to the initial WordPress set-up state (deleting all site content stored in tha...Show more |
1Webfactoryltd 1Wp Database Reset Nov 21, 2024 Jan 16, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The WordPress plugin, WP Database Reset through 3.1, contains a flaw that gave any authenticated user, with minimal permissions, the ability (with a simple wp-admin/admin.php?db-reset-tables[]=users request) to escalate...Show more |