Adminer [adminer] < 1.4.5
unknown
[en] A vulnerability has been found in Adminer Login 1.4.4 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to improper access controls. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.
- Affected:
- up to 1.4.5
- Fixed in:
- 1.4.5
- Disclosed:
- Jun 20, 2022
CVE-2017-20066 on NVD →
Adminer <= 1.4.5 - Security Bypass to Database Login
critical
The Adminer plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the adminer_load_editor() function in versions up to, and including, 1.4.5. This makes it possible for unauthenticated (no login required) attackers to access any database associated with the vulnerable WordPress...
- CVSS:
- 9.8
- Affected:
- up to 1.4.5
- Fix:
- No patched version reported
- Disclosed:
- Mar 3, 2017
CVE-2017-20066 on NVD →
Adminer < 1.4.4 - Cross-Site Scripting
high
The Adminer plugin for WordPress is vulnerable to Cross-Site Scripting in the altar table versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 7.2
- Affected:
- up to 1.4.4
- Fixed in:
- 1.4.4
- Disclosed:
- Mar 4, 2016
Adminer [adminer] < 1.4.4
unknown
The Adminer plugin for WordPress is vulnerable to Cross-Site Scripting in the altar table versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- Affected:
- up to 1.4.4
- Fixed in:
- 1.4.4
- Disclosed:
- Mar 4, 2016
Adminer [adminer] <= 1.4.5 (unfixed + closed)
unknown
The plugin is still affected and has been closed.
- Affected:
- up to 1.4.5
- Fix:
- No patched version reported
Adminer [adminer] < 1.4.4 (closed)
unknown
The adminer WordPress plugin was affected by a Multiple Cross-Site Scripting (XSS) Issue security vulnerability.
- Affected:
- up to 1.4.4
- Fixed in:
- 1.4.4
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database