Critical severity9.1NVD Advisory· Published Jan 16, 2020· Updated Jun 17, 2026
CVE-2020-7048
CVE-2020-7048
Description
The WordPress plugin, WP Database Reset through 3.1, contains a flaw that allowed any unauthenticated user to reset any table in the database to the initial WordPress set-up state (deleting all site content stored in that table), as demonstrated by a wp-admin/admin-post.php?db-reset-tables[]=comments URI.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:webfactoryltd:wp_database_reset:*:*:*:*:*:wordpress:*:*Range: <=3.1
- WordPress/WP Database Resetdescription
- Range: <=3.1
Patches
Vulnerability mechanics
References
3- www.wordfence.com/blog/2020/01/easily-exploitable-vulnerabilities-patched-in-wp-database-reset-plugin/nvdExploitPatchThird Party Advisory
- wordpress.org/plugins/wordpress-database-reset/nvdRelease NotesThird Party Advisory
- wpvulndb.com/vulnerabilities/10027nvdThird Party Advisory
News mentions
0No linked articles in our index yet.