The Database Reset plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.22. This is due to missing or incorrect nonce validation on the install_wpr() function. This makes it possible for unauthenticated attackers to install the WP Reset Plugin via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
oryginał ENCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:NWebfactoryltd Wp Database Reset
APPWebfactoryltd< 3.23
Powiązane podatności
WP Database Reset: reset tabel bazy danych bez uwierzytelnienia
The WordPress plugin, WP Database Reset through 3.1, contains a flaw that gave any authenticated user, with mi...
301 Redirects dla WordPress — nieautoryzowana modyfikacja reguł i XSS
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WebFacto...
Cross-Site Request Forgery (CSRF) vulnerability in WebFactory Ltd. WP Reset PRO plugin <= 5.98 versions.