plugin

Rvg Optimize Database Vulnerabilities

7 known security issues reported for the Rvg Optimize Database WordPress plugin. Most recent disclosed Oct 4, 2023.

3 medium

Running Rvg Optimize Database on your site? Check whether your installed version is affected.

Scan your site free

Optimize Database after Deleting Revisions [rvg-optimize-database] < 5.1.1

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in CAGE Web Design | Rolf van Gelder Optimize Database after Deleting Revisions plugin <= 5.1 versions.

Affected:
up to 5.1.1
Fixed in:
5.1.1
Disclosed:
Oct 4, 2023

CVE-2023-25980 on NVD →

Optimize Database after Deleting Revisions [rvg-optimize-database] < 5.1

unknown

Update the WordPress Optimize Database after Deleting Revisions plugin to the latest available version (at least 5.1). WordFence discovered and reported this Broken Access Control vulnerability in WordPress Optimize Database after Deleting Revisions Plugin. A broken access control issue refers to a missing authorizatio...

Affected:
up to 5.1
Fixed in:
5.1
Disclosed:
Oct 4, 2023

Optimize Database after Deleting Revisions <= 5.0.110 - Missing Authorization via 'odb_csv_download'

medium

The Optimize Database after Deleting Revisions plugin for WordPress is vulnerable to information disclosure in versions up to, and including, 5.0.110. This is due to a missing capability check on the 'odb_csv_download' function which is hooked via admin_init. This makes it possible for unauthenticated attackers to trig...

CVSS:
5.3
Affected:
up to 5.0.110
Fixed in:
5.1
Disclosed:
Oct 3, 2023

Optimize Database after Deleting Revisions [rvg-optimize-database] < 5.1

unknown

The Optimize Database after Deleting Revisions plugin for WordPress is vulnerable to information disclosure in versions up to, and including, 5.0.110. This is due to a missing capability check on the 'odb_csv_download' function which is hooked via admin_init. This makes it possible for unauthenticated attackers to trig...

Affected:
up to 5.1
Fixed in:
5.1
Disclosed:
Oct 3, 2023

Optimize Database after Deleting Revisions <= 5.1.1 - Cross-Site Request Forgery via 'odb_start_manually'

medium

The Optimize Database after Deleting Revisions plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.1 This is due to missing or incorrect nonce validation on the ‘odb_start_manually’ function. This makes it possible for unauthenticated attackers to start the database op...

CVSS:
4.3
Affected:
up to 5.1.1
Fixed in:
5.2
Disclosed:
Jul 26, 2023

CVE-2023-25980 on NVD →

Optimize Database after Deleting Revisions <= 5.0.110 - Cross-Site Request Forgery via 'odb_csv_download'

medium

The Optimize Database after Deleting Revisions plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.0.110. This is due to missing or incorrect nonce validation on the 'odb_csv_download' function. This makes it possible for unauthenticated attackers to trigger a download o...

CVSS:
4.3
Affected:
up to 5.0.110
Fixed in:
5.1
Disclosed:
Jul 26, 2023

Optimize Database after Deleting Revisions [rvg-optimize-database] < 5.1

unknown

The Optimize Database after Deleting Revisions plugin for WordPress is vulnerable to information disclosure in versions up to, and including, 5.0.110. This is due to a missing capability check on the &#039;odb_csv_download&#039; function which is hooked via admin_init. This makes it possible for unauthenticated attacke...

Affected:
up to 5.1
Fixed in:
5.1

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database