Optimize Database after Deleting Revisions [rvg-optimize-database] < 5.1.1
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in CAGE Web Design | Rolf van Gelder Optimize Database after Deleting Revisions plugin <= 5.1 versions.
- Affected:
- up to 5.1.1
- Fixed in:
- 5.1.1
- Disclosed:
- Oct 4, 2023
CVE-2023-25980 on NVD →
Optimize Database after Deleting Revisions [rvg-optimize-database] < 5.1
unknown
Update the WordPress Optimize Database after Deleting Revisions plugin to the latest available version (at least 5.1).
WordFence discovered and reported this Broken Access Control vulnerability in WordPress Optimize Database after Deleting Revisions Plugin. A broken access control issue refers to a missing authorizatio...
- Affected:
- up to 5.1
- Fixed in:
- 5.1
- Disclosed:
- Oct 4, 2023
Optimize Database after Deleting Revisions <= 5.0.110 - Missing Authorization via 'odb_csv_download'
medium
The Optimize Database after Deleting Revisions plugin for WordPress is vulnerable to information disclosure in versions up to, and including, 5.0.110. This is due to a missing capability check on the 'odb_csv_download' function which is hooked via admin_init. This makes it possible for unauthenticated attackers to trig...
- CVSS:
- 5.3
- Affected:
- up to 5.0.110
- Fixed in:
- 5.1
- Disclosed:
- Oct 3, 2023
Optimize Database after Deleting Revisions [rvg-optimize-database] < 5.1
unknown
The Optimize Database after Deleting Revisions plugin for WordPress is vulnerable to information disclosure in versions up to, and including, 5.0.110. This is due to a missing capability check on the 'odb_csv_download' function which is hooked via admin_init. This makes it possible for unauthenticated attackers to trig...
- Affected:
- up to 5.1
- Fixed in:
- 5.1
- Disclosed:
- Oct 3, 2023
Optimize Database after Deleting Revisions <= 5.1.1 - Cross-Site Request Forgery via 'odb_start_manually'
medium
The Optimize Database after Deleting Revisions plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.1 This is due to missing or incorrect nonce validation on the ‘odb_start_manually’ function. This makes it possible for unauthenticated attackers to start the database op...
- CVSS:
- 4.3
- Affected:
- up to 5.1.1
- Fixed in:
- 5.2
- Disclosed:
- Jul 26, 2023
CVE-2023-25980 on NVD →
Optimize Database after Deleting Revisions <= 5.0.110 - Cross-Site Request Forgery via 'odb_csv_download'
medium
The Optimize Database after Deleting Revisions plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.0.110. This is due to missing or incorrect nonce validation on the 'odb_csv_download' function. This makes it possible for unauthenticated attackers to trigger a download o...
- CVSS:
- 4.3
- Affected:
- up to 5.0.110
- Fixed in:
- 5.1
- Disclosed:
- Jul 26, 2023
Optimize Database after Deleting Revisions [rvg-optimize-database] < 5.1
unknown
The Optimize Database after Deleting Revisions plugin for WordPress is vulnerable to information disclosure in versions up to, and including, 5.0.110. This is due to a missing capability check on the 'odb_csv_download' function which is hooked via admin_init. This makes it possible for unauthenticated attacke...
- Affected:
- up to 5.1
- Fixed in:
- 5.1
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database