Custom Searchable Data Entry System
cpe:2.3:a:custom_searchable_data_entry_system_project:custom_searchable_data_entry_system:*:*:*:*:wordpress:*:*
- <= 1.7.1
This vulnerability is being actively exploited in the wild.
A vulnerability exists in the Custom Searchable Data Entry System plugin for WordPress, in versions through 1.7.1. The issue allows unauthenticated users to wipe database tables, including wp_users, due to a missing capability check and inadequate validation in the ghazale_sds_delete_entries_table_row() function.
Exploitation of this vulnerability allows for unauthenticated users to delete entries from database tables, potentially including critical tables like wp_users.
The plugin has been removed from the WordPress repository and is no longer available for download. Users are advised to deactivate and delete the plugin from their WordPress installation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.