Advanced Database Cleaner <= 3.1.6 - Cross-Site Request Forgery
medium
The Advanced Database Cleaner – Optimize & Clean Database to Speed Up Site Performance plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.6. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to...
- CVSS:
- 4.3
- Affected:
- up to 3.1.6
- Fixed in:
- 3.1.7
- Disclosed:
- Oct 30, 2025
CVE-2025-64357 on NVD →
Advanced Database Cleaner <= 3.1.6 - Cross-Site Request Forgery to Settings Manipulation
medium
The Advanced Database Cleaner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.6. This is due to missing or incorrect nonce validation on the aDBc_prepare_elements_to_clean() function. This makes it possible for unauthenticated attackers to alter the keep last s...
- CVSS:
- 4.3
- Affected:
- up to 3.1.6
- Fixed in:
- 3.1.7
- Disclosed:
- Oct 24, 2025
CVE-2025-11497 on NVD →
Advanced Database Cleaner <= 3.1.3 - Authenticated(Administrator+) PHP Object Injection via process_bulk_action
medium
The Advanced Database Cleaner plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.1.3 via deserialization of untrusted input in the 'process_bulk_action' function. This makes it possible for authenticated attacker, with administrator access and above, to inject a PHP Objec...
- CVSS:
- 6.6
- Affected:
- up to 3.1.3
- Fixed in:
- 3.1.4
- Disclosed:
- Jan 24, 2024
CVE-2024-0668 on NVD →
Advanced Database Cleaner <= 3.1.2 - Authenticated (Administrator+) SQL Injection
high
The Advanced Database Cleaner plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in versions up to, and including, 3.1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attack...
- CVSS:
- 7.2
- Affected:
- up to 3.1.2
- Fixed in:
- 3.1.3
- Disclosed:
- Dec 4, 2023
CVE-2023-49764 on NVD →
Advanced Database Cleaner <= 3.1.1 - Cross-Site Request Forgery via aDBc_save_settings_callback
medium
The Advanced Database Cleaner plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1.1. This is due to missing or incorrect nonce validation on the aDBc_save_settings_callback function. This makes it possible for unauthenticated attackers to change plugin settings via a f...
- CVSS:
- 4.3
- Affected:
- up to 3.1.1
- Fixed in:
- 3.1.2
- Disclosed:
- Feb 21, 2023
CVE-2022-46813 on NVD →
Advanced Database Cleaner <= 3.1.0 - Reflected Cross-Site Scripting
medium
The Advanced Database Cleaner WordPress plugin before 3.1.1 does not escape numerous generated URLs before outputting them back in href attributes of admin dashboard pages, leading to Reflected Cross-Site Scripting
- CVSS:
- 6.1
- Affected:
- up to 3.1.0
- Fixed in:
- 3.1.1
- Disclosed:
- Jun 27, 2022
CVE-2022-2173 on NVD →
Advanced Database Cleaner <= 3.0.3 - Reflected Cross-Site Scripting
medium
The Advanced Database Cleaner WordPress plugin before 3.0.4 does not sanitise and escape $_GET keys and values before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues
- CVSS:
- 6.1
- Affected:
- up to 3.0.4
- Fixed in:
- 3.0.4
- Disclosed:
- Jan 24, 2022
CVE-2021-24921 on NVD →
Advanced Database Cleaner <= 3.0.1 - SQL injection
high
Unvaludated input in the Advanced Database Cleaner plugin, versions before 3.0.2, lead to SQL injection allowing high privilege users (admin+) to perform SQL attacks.
- CVSS:
- 7.2
- Affected:
- up to 3.0.2
- Fixed in:
- 3.0.2
- Disclosed:
- Sep 6, 2020
CVE-2021-24141 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database