The Custom Searchable Data Entry System plugin for WordPress is vulnerable to unauthenticated database wiping in versions up to, and including 1.7.1, due to a missing capability check and lack of sufficient validation on the ghazale_sds_delete_entries_table_row() function. This makes it possible for unauthenticated attackers to completely wipe database tables such as wp_users.
Metrics
Affected Vendors & Products
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 01 Oct 2025 06:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Custom Searchable Data Entry System plugin for WordPress is vulnerable to unauthenticated database wiping in versions up to, and including 1.7.1, due to a missing capability check and lack of sufficient validation on the ghazale_sds_delete_entries_table_row() function. This makes it possible for unauthenticated attackers to completely wipe database tables such as wp_users. | |
Title | Custom Searchable Data Entry System <= 1.7.1 - Unauthenticated Database Wiping | |
Weaknesses | CWE-862 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-10-01T06:42:25.437Z
Reserved: 2025-09-30T17:58:55.506Z
Link: CVE-2020-36852

No data.

Status : Received
Published: 2025-10-01T07:15:44.083
Modified: 2025-10-01T07:15:44.083
Link: CVE-2020-36852

No data.

No data.