Sensitive Information Exposure in WP Reset Plugin for WordPress
CVE-2025-10645
5.3MEDIUM
What is CVE-2025-10645?
The WP Reset plugin for WordPress has a vulnerability that allows unauthenticated attackers to access sensitive information, including license keys and site data. This issue arises from the WF_Licensing::log() method when debugging is enabled by default. Attackers can exploit this vulnerability to extract confidential data, posing a risk to site security and integrity.
Affected Version(s)
WP Reset * <= 2.05