plugin

Adminer Vulnerabilities

6 known security issues reported for the Adminer WordPress plugin. Most recent disclosed Jun 20, 2022.

1 critical 1 high

Running Adminer on your site? Check whether your installed version is affected.

Scan your site free

Adminer [adminer] < 1.4.5

unknown

[en] A vulnerability has been found in Adminer Login 1.4.4 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to improper access controls. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.

Affected:
up to 1.4.5
Fixed in:
1.4.5
Disclosed:
Jun 20, 2022

CVE-2017-20066 on NVD →

Adminer <= 1.4.5 - Security Bypass to Database Login

critical

The Adminer plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the adminer_load_editor() function in versions up to, and including, 1.4.5. This makes it possible for unauthenticated (no login required) attackers to access any database associated with the vulnerable WordPress...

CVSS:
9.8
Affected:
up to 1.4.5
Fix:
No patched version reported
Disclosed:
Mar 3, 2017

CVE-2017-20066 on NVD →

Adminer < 1.4.4 - Cross-Site Scripting

high

The Adminer plugin for WordPress is vulnerable to Cross-Site Scripting in the altar table versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
7.2
Affected:
up to 1.4.4
Fixed in:
1.4.4
Disclosed:
Mar 4, 2016

Adminer [adminer] < 1.4.4

unknown

The Adminer plugin for WordPress is vulnerable to Cross-Site Scripting in the altar table versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

Affected:
up to 1.4.4
Fixed in:
1.4.4
Disclosed:
Mar 4, 2016

Adminer [adminer] <= 1.4.5 (unfixed + closed)

unknown

The plugin is still affected and has been closed.

Affected:
up to 1.4.5
Fix:
No patched version reported

Adminer [adminer] < 1.4.4 (closed)

unknown

The adminer WordPress plugin was affected by a Multiple Cross-Site Scripting (XSS) Issue security vulnerability.

Affected:
up to 1.4.4
Fixed in:
1.4.4

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database