Cross-Site Request Forgery (CSRF) vulnerability leading to Database Reset in WordPress WP Reset PRO Premium plugin (versions <= 5.98) allows attackers to trick authenticated into making unintentional database reset.
References
| Link | Resource |
|---|---|
| https://wpreset.com/changelog/ | Release Notes Vendor Advisory |
| https://patchstack.com/wp-reset-pro-critical-vulnerability-fixed/ | Exploit Third Party Advisory |
| https://patchstack.com/database/vulnerability/wp-reset/wordpress-wp-reset-pro-premium-plugin-5-98-cross-site-request-forgery-csrf-vulnerability-leading-to-database-reset | Third Party Advisory |
Configurations
Information
Published : 2021-11-18 15:15
Updated : 2021-11-19 21:56
NVD link : CVE-2021-36908
Mitre link : CVE-2021-36908
JSON object : View
Products Affected
webfactoryltd
- wp_reset_pro
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
