Description
The WP Reset plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_ajax function in all versions up to, and including, 2.02. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify the value fo the 'License Key' field for the 'Activate Pro License' setting.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-44263 | The WP Reset plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_ajax function in all versions up to, and including, 2.02. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify the value fo the 'License Key' field for the 'Activate Pro License' setting. |
References
History
Wed, 08 Apr 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:webfactoryltd:wp_reset:*:*:*:*:*:*:*:* | |
| Metrics |
ssvc
|
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 31 Oct 2024 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Webfactoryltd
Webfactoryltd wp Reset |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:webfactoryltd:wp_reset:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Webfactoryltd
Webfactoryltd wp Reset |
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:35:14.789Z
Reserved: 2024-05-08T16:44:06.019Z
Link: CVE-2024-4661
Updated: 2024-08-01T20:47:41.503Z
Status : Modified
Published: 2024-06-08T06:15:09.463
Modified: 2026-04-08T17:18:56.660
Link: CVE-2024-4661
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD