Database Cleaner <= 1.0.5 - Authenticated (Admin+) Arbitrary File Read
medium
The Database Cleaner: Clean, Optimize & Repair plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 1.0.5 via the get_logs() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive inform...
- CVSS:
- 4.9
- Affected:
- up to 1.0.5
- Fixed in:
- 1.0.6
- Disclosed:
- Jun 6, 2024
CVE-2024-35712 on NVD →
Database Cleaner <= 0.9.8 - Sensitive Information Exposure via Log File
medium
The Database Cleaner: Clean, Optimize & Repair plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 0.9.8 via the plugin's log file. This makes it possible for unauthenticated attackers to extract sensitive data including system and plugin configuration.
- CVSS:
- 5.3
- Affected:
- up to 0.9.8
- Fixed in:
- 0.9.9
- Disclosed:
- Dec 27, 2023
CVE-2023-51508 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database