First published: Thu Nov 18 2021(Updated: )
Authenticated Database Reset vulnerability in WordPress WP Reset PRO Premium plugin (versions <= 5.98) allows any authenticated user to wipe the entire database regardless of their authorization. It leads to a complete website reset and takeover.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WP Reset Pro | <=5.98 |
Update to 5.99 or higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-36909 is rated as a critical vulnerability due to its potential to allow any authenticated user to wipe the entire database.
To fix CVE-2021-36909, upgrade the WP Reset PRO Premium plugin to version 5.99 or later.
Any user of the WP Reset PRO Premium plugin version 5.98 or earlier with authenticated access is affected by CVE-2021-36909.
CVE-2021-36909 is an authenticated database reset vulnerability that allows unauthorized database wipe capabilities.
Exploiting CVE-2021-36909 can lead to a complete website reset and potential takeover of the site.