216.73.216.6

CVE-2020-36852

· Published 01/10/2025 07:15 · Modified 02/10/2025 19:12

Labels: CVE-2020-36852 2025-10-01CVE-2020-36852CWE-862[email protected]

Essential information

Published
01/10/2025 07:15
Modified
02/10/2025 19:12
Author
Creator
CVSS
9.1 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

CVSS metrics

Description

The Custom Searchable Data Entry System plugin for WordPress is vulnerable to unauthenticated database wiping in versions up to, and including 1.7.1, due to a missing capability check and lack of sufficient validation on the ghazale_sds_delete_entries_table_row() function. This makes it possible for unauthenticated attackers to completely wipe database tables such as wp_users.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
wordpress / custom searchable data entry system cpe:2.3:a:wordpress:custom_searchable_data_entry_system:1.7.1:*:*:*:*:wordpress:*:*
wordpress / custom searchable data entry system cpe:2.3:a:wordpress:custom_searchable_data_entry_system:*:*:*:*:*:wordpress:*:*

References