The Custom Searchable Data Entry System plugin for WordPress is vulnerable to unauthenticated database wiping in versions up to, and including 1.7.1, due to a missing capability check and lack of sufficient validation on the ghazale_sds_delete_entries_table_row() function. This makes it possible for unauthenticated attackers to completely wipe database tables such as wp_users.
Metrics
Affected Vendors & Products
References
History
Thu, 02 Oct 2025 09:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Custom Searchable Data Entry System Project
Custom Searchable Data Entry System Project custom Searchable Data Entry System Wordpress Wordpress wordpress |
|
Vendors & Products |
Custom Searchable Data Entry System Project
Custom Searchable Data Entry System Project custom Searchable Data Entry System Wordpress Wordpress wordpress |
Wed, 01 Oct 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 01 Oct 2025 06:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Custom Searchable Data Entry System plugin for WordPress is vulnerable to unauthenticated database wiping in versions up to, and including 1.7.1, due to a missing capability check and lack of sufficient validation on the ghazale_sds_delete_entries_table_row() function. This makes it possible for unauthenticated attackers to completely wipe database tables such as wp_users. | |
Title | Custom Searchable Data Entry System <= 1.7.1 - Unauthenticated Database Wiping | |
Weaknesses | CWE-862 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-10-01T13:17:53.788Z
Reserved: 2025-09-30T17:58:55.506Z
Link: CVE-2020-36852

Updated: 2025-10-01T13:17:50.352Z

Status : Awaiting Analysis
Published: 2025-10-01T07:15:44.083
Modified: 2025-10-02T19:12:17.160
Link: CVE-2020-36852

No data.