WP Reset Plugin Sensitive Information Exposure Vulnerability

Vulnerability

A vulnerability allowing sensitive information exposure has been identified in the WP Reset plugin for WordPress, affecting all versions through 2.05. When debugging is enabled, the WF_Licensing::log() method can be exploited by unauthenticated attackers to access sensitive license keys and site data.

Impact

Exploitation of this vulnerability allows unauthenticated attackers to access sensitive license information and site data.

Remediation

Users are advised to update the WP Reset plugin to version 2.06 or a newer patched version.

Added: Oct 7, 2025, 9:18 AM
Updated: Oct 7, 2025, 9:18 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.1
remediation
7.7
relevance
0.6
threat
3.2
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.