plugin

Advanced Database Cleaner Vulnerabilities

8 known security issues reported for the Advanced Database Cleaner WordPress plugin. Most recent disclosed Oct 30, 2025.

2 high 6 medium

Running Advanced Database Cleaner on your site? Check whether your installed version is affected.

Scan your site free

Advanced Database Cleaner <= 3.1.6 - Cross-Site Request Forgery

medium

The Advanced Database Cleaner – Optimize & Clean Database to Speed Up Site Performance plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.6. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to...

CVSS:
4.3
Affected:
up to 3.1.6
Fixed in:
3.1.7
Disclosed:
Oct 30, 2025

CVE-2025-64357 on NVD →

Advanced Database Cleaner <= 3.1.6 - Cross-Site Request Forgery to Settings Manipulation

medium

The Advanced Database Cleaner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.6. This is due to missing or incorrect nonce validation on the aDBc_prepare_elements_to_clean() function. This makes it possible for unauthenticated attackers to alter the keep last s...

CVSS:
4.3
Affected:
up to 3.1.6
Fixed in:
3.1.7
Disclosed:
Oct 24, 2025

CVE-2025-11497 on NVD →

Advanced Database Cleaner <= 3.1.3 - Authenticated(Administrator+) PHP Object Injection via process_bulk_action

medium

The Advanced Database Cleaner plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.1.3 via deserialization of untrusted input in the 'process_bulk_action' function. This makes it possible for authenticated attacker, with administrator access and above, to inject a PHP Objec...

CVSS:
6.6
Affected:
up to 3.1.3
Fixed in:
3.1.4
Disclosed:
Jan 24, 2024

CVE-2024-0668 on NVD →

Advanced Database Cleaner <= 3.1.2 - Authenticated (Administrator+) SQL Injection

high

The Advanced Database Cleaner plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in versions up to, and including, 3.1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attack...

CVSS:
7.2
Affected:
up to 3.1.2
Fixed in:
3.1.3
Disclosed:
Dec 4, 2023

CVE-2023-49764 on NVD →

Advanced Database Cleaner <= 3.1.1 - Cross-Site Request Forgery via aDBc_save_settings_callback

medium

The Advanced Database Cleaner plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1.1. This is due to missing or incorrect nonce validation on the aDBc_save_settings_callback function. This makes it possible for unauthenticated attackers to change plugin settings via a f...

CVSS:
4.3
Affected:
up to 3.1.1
Fixed in:
3.1.2
Disclosed:
Feb 21, 2023

CVE-2022-46813 on NVD →

Advanced Database Cleaner <= 3.1.0 - Reflected Cross-Site Scripting

medium

The Advanced Database Cleaner WordPress plugin before 3.1.1 does not escape numerous generated URLs before outputting them back in href attributes of admin dashboard pages, leading to Reflected Cross-Site Scripting

CVSS:
6.1
Affected:
up to 3.1.0
Fixed in:
3.1.1
Disclosed:
Jun 27, 2022

CVE-2022-2173 on NVD →

Advanced Database Cleaner <= 3.0.3 - Reflected Cross-Site Scripting

medium

The Advanced Database Cleaner WordPress plugin before 3.0.4 does not sanitise and escape $_GET keys and values before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues

CVSS:
6.1
Affected:
up to 3.0.4
Fixed in:
3.0.4
Disclosed:
Jan 24, 2022

CVE-2021-24921 on NVD →

Advanced Database Cleaner <= 3.0.1 - SQL injection

high

Unvaludated input in the Advanced Database Cleaner plugin, versions before 3.0.2, lead to SQL injection allowing high privilege users (admin+) to perform SQL attacks.

CVSS:
7.2
Affected:
up to 3.0.2
Fixed in:
3.0.2
Disclosed:
Sep 6, 2020

CVE-2021-24141 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database