Cross-Site Request Forgery (CSRF) vulnerability leading to Database Reset in WordPress WP Reset PRO Premium plugin (versions <= 5.98) allows attackers to trick authenticated into making unintentional database reset.
References
Link | Resource |
---|---|
https://wpreset.com/changelog/ | Release Notes Vendor Advisory |
https://patchstack.com/wp-reset-pro-critical-vulnerability-fixed/ | Exploit Third Party Advisory |
https://patchstack.com/database/vulnerability/wp-reset/wordpress-wp-reset-pro-premium-plugin-5-98-cross-site-request-forgery-csrf-vulnerability-leading-to-database-reset | Third Party Advisory |
Configurations
Information
Published : 2021-11-18 07:15
Updated : 2021-11-19 13:56
NVD link : CVE-2021-36908
Mitre link : CVE-2021-36908
JSON object : View
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
Products Affected
webfactoryltd
- wp_reset_pro