WP Database Reset <= 3.1 - Unauthenticated Database Reset
Strategic Overview
- Status
- Patched in 3.15
- Affected Plugin
- Database Reset
- Affected Version
<= 3.1- CVSS
- 9.1Critical
- Weakness type
- CWE-287 · Improper Authentication
- CVE
CVE-2020-7048
At a glance
CVE-2020-7048 is a critical-severity Improper Authentication vulnerability in the Database Reset WordPress plugin, affecting versions <= 3.1. It carries a CVSS score of 9.1 (reachable over the network; low attack complexity; high integrity, availability impact). Exploitation requires no authentication. The issue is fixed in version 3.15; sites on affected versions should update now. Disclosed January 2020, reported by Chloe Chamberland.
Vulnerability Overview
The WordPress plugin, WP Database Reset through 3.1, contains a flaw that allowed any unauthenticated user to reset any table in the database to the initial WordPress set-up state (deleting all site content stored in that table), as demonstrated by a wp-admin/admin-post.php?db-reset-tables[]=comments URI.
Technical Analysis
The vector marks this flaw as remotely reachable over the network, with low attack complexity — no special timing or configuration is needed, and no privileges on the target site, and no interaction from a victim user. A successful exploit has high impact on integrity, availability.
CWE-287: Improper Authentication
Reaching this weakness in Database Reset <= 3.1 takes no account at all. Improper authentication means the mechanism that proves who a caller is can be satisfied without the secret it was supposed to require.
An attacker authenticates as another user — administrators included — without ever knowing a password, so password policies and login rate limits never come into play. For Database Reset the fix is 3.15: builds <= 3.1 are affected, anything from 3.15 onward is not.
Remediation
Update to version 3.15, or a newer patched version
How does WordSec protect against this?
This one needs no account at all, which puts it outside what login hardening can reach; WordSec's login security narrows the account-level paths around it, and the firewall is what inspects the request itself. None of that substitutes for the fix: Database Reset 3.15 closes this, and updating the plugin is the step that ends it.
- Login Security
- Alerts
External References
Related records
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C