plugin

Wp Dbmanager Vulnerabilities

12 known security issues reported for the Wp Dbmanager WordPress plugin. Most recent disclosed Aug 15, 2022.

4 high 1 medium

Running Wp Dbmanager on your site? Check whether your installed version is affected.

Scan your site free

WP-DBManager [wp-dbmanager] < 2.80.8

unknown

[en] The WP-DBManager WordPress plugin before 2.80.8 does not prevent administrators from running arbitrary commands on the server in multisite installations, where only super-administrators should.

Affected:
up to 2.80.8
Fixed in:
2.80.8
Disclosed:
Aug 15, 2022

CVE-2022-2354 on NVD →

WP-DBManager <= 2.80.7 - Authenticated (Admin+) Remote Code Execution on Multi-Site

high

The WP-DBManager plugin for WordPress is vulnerable to remote code execution due to an incorrect capability check in the ~/database-backup.php file in versions up to, and including, 2.80.7. This makes it possible for high level authenticated users, such as administrators, to run arbitrary commands on the affected serve...

CVSS:
7.2
Affected:
up to 2.80.7
Fixed in:
2.80.8
Disclosed:
Jul 25, 2022

CVE-2022-2354 on NVD →

WP-DBManager [wp-dbmanager] < 2.79.2

unknown

Arbitrary File Deletion vulnerability found by RIPS in WordPress WP-DBManager plugin (versions <= 2.79.1).

Affected:
up to 2.79.2
Fixed in:
2.79.2
Disclosed:
Nov 27, 2018

WP-DBManager <= 2.79.1 - Directory Traversal Allowing Arbitrary File Deletion

high

The WP-DBManager plugin for WordPress is vulnerable to Directory Traversal allowing arbitrary file deletion in versions up to, and including, 2.79.1. This allows authenticated high-privilege attackers to delete arbitrary files, which can be used to reset a site and gain administrative access.

CVSS:
8.7
Affected:
up to 2.79.2
Fixed in:
2.79.2
Disclosed:
Oct 22, 2018

WP-DBManager [wp-dbmanager] < 2.79.2

unknown

The WP-DBManager plugin for WordPress is vulnerable to Directory Traversal allowing arbitrary file deletion in versions up to, and including, 2.79.1. This allows authenticated high-privilege attackers to delete arbitrary files, which can be used to reset a site and gain administrative access.

Affected:
up to 2.79.2
Fixed in:
2.79.2
Disclosed:
Oct 22, 2018

WP-DBManager [wp-dbmanager] < 2.72

unknown

[en] (1) wp-dbmanager.php and (2) database-manage.php in the WP-DBManager (aka Database Manager) plugin before 2.7.2 for WordPress place credentials on the mysqldump command line, which allows local users to obtain sensitive information by listing the process.

Affected:
up to 2.72
Fixed in:
2.72
Disclosed:
Jan 5, 2018

CVE-2014-8335 on NVD →

WP-DBManager [wp-dbmanager] < 2.7.2

unknown

[en] The "Sql Run Query" panel in WP-DBManager (aka Database Manager) plugin before 2.7.2 for WordPress allows remote attackers to read arbitrary files by leveraging failure to sufficiently limit queries, as demonstrated by use of LOAD_FILE in an INSERT statement.

Affected:
up to 2.7.2
Fixed in:
2.7.2
Disclosed:
Jan 5, 2018

CVE-2014-8336 on NVD →

WP-DBManager [wp-dbmanager] < 2.72

unknown

[en] The WP-DBManager (aka Database Manager) plugin before 2.7.2 for WordPress allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) $backup['filepath'] (aka "Path to Backup:" field) or (2) $backup['mysqldumppath'] variable.

Affected:
up to 2.72
Fixed in:
2.72
Disclosed:
Oct 31, 2014

CVE-2014-8334 on NVD →

WP-DBManager < 2.72 - Command Injection

high

(1) wp-dbmanager.php and (2) database-manage.php in the WP-DBManager (aka Database Manager) plugin before 2.72 for WordPress place credentials on the mysqldump command line, which allows local users to obtain sensitive information by listing the process.

CVSS:
8.8
Affected:
up to 2.72
Fixed in:
2.72
Disclosed:
Oct 13, 2014

CVE-2014-8335 on NVD →

WP-DBManager < 2.72 - OS Command Injection

high

The WP-DBManager (aka Database Manager) plugin before 2.72 for WordPress allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) $backup['filepath'] (aka "Path to Backup:" field) or (2) $backup['mysqldumppath'] variable.

CVSS:
7.8
Affected:
up to 2.72
Fixed in:
2.72
Disclosed:
Oct 13, 2014

CVE-2014-8334 on NVD →

WP DB Manager < 2.7.2 - Arbitrary File Read

medium

The "Sql Run Query" panel in WP-DBManager (aka Database Manager) plugin before 2.7.2 for WordPress allows remote attackers to read arbitrary files by leveraging failure to sufficiently limit queries, as demonstrated by use of LOAD_FILE in an INSERT statement.

CVSS:
6.5
Affected:
up to 2.7.2
Fixed in:
2.7.2
Disclosed:
Oct 13, 2014

CVE-2014-8336 on NVD →

WP-DBManager [wp-dbmanager] < 2.79.2

unknown

The WP-DBManager WordPress plugin was affected by an Arbitrary File Delete security vulnerability.

Affected:
up to 2.79.2
Fixed in:
2.79.2

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database