The WP Reset – Most Advanced WordPress Reset Tool plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0 via the use of insufficiently random snapshot names. This makes it possible for unauthenticated attackers to extract sensitive data including site backups by brute-forcing the snapshot filenames. Please note that the vendor does not plan to do any further hardening on this functionality.
References
Configurations
History
07 Apr 2025, 14:03
Type | Values Removed | Values Added |
---|---|---|
References | () https://plugins.trac.wordpress.org/changeset?old_path=/wp-reset/tags/1.99&old=3059287&new_path=/wp-reset/tags/2.0&new=3059287&sfp_email=&sfph_mail= - Product | |
References | () https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3071811%40wp-reset&new=3071811%40wp-reset&sfp_email=&sfph_mail= - Patch | |
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/68f41e88-ed36-4361-bddd-41495a540cd9?source=cve - Third Party Advisory | |
CPE | cpe:2.3:a:webfactoryltd:wp_reset:*:*:*:*:*:wordpress:*:* | |
First Time |
Webfactoryltd
Webfactoryltd wp Reset |
26 Feb 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-330 |
Information
Published : 2024-04-09 19:15
Updated : 2025-04-07 14:03
NVD link : CVE-2023-6799
Mitre link : CVE-2023-6799
CVE.ORG link : CVE-2023-6799
JSON object : View
Products Affected
webfactoryltd
- wp_reset
CWE
CWE-330
Use of Insufficiently Random Values