nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-7047 CVE-2020-7047
HIGH
webfactoryltd wp_database_reset Improper Privilege Management
Record summary
CVE-2020-7047 has a selected CVSS score of 8.8 (high).
Description
The WordPress plugin, WP Database Reset through 3.1, contains a flaw that gave any authenticated user, with minimal permissions, the ability (with a simple wp-admin/admin.php?db-reset-tables[]=users request) to escalate their privileges to administrator while dropping all other users from the table.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jan 16, 2020 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
wp_database_resetBrowse webfactoryltd / wp_database_reset | VulnCheck | Version data not supplied | |
References
4wordpress.org
https://wordpress.org/plugins/wordpress-database-reset wpvulndb.com
https://wpvulndb.com/vulnerabilities/10028 wordfence.com
https://www.wordfence.com/blog/2020/01/easily-exploitable-vulnerabilities-patched-in-wp-database-reset-plugin