Showing 1 vulnerability on this page for wp_reset

Signals CISA KEV Ransomware Nuclei
webfactoryltd vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

WP Reset <= 2.02 - Missing Authorization to License Key Modification

The WP Reset plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_ajax function in all versions up to, and including, 2.02. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify the value fo the 'License Key' field for the 'Activate Pro License' setting.

CWE-862Jun 8, 2024
CVSS4.3v3.1EPSS0.28%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX