Advanced Database Cleaner PRO <= 3.2.10 - Authenticated (Subscriber+) Limited Path Traversal
mediumThe advanced-database-cleaner-pro plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 3.2.10. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform actions on .txt files outside of the originally intended directory.
- CVSS:
- 4.3
- Affected:
- up to 3.2.10
- Fixed in:
- 3.2.11
- Disclosed:
- May 22, 2025