WP-DBManager [wp-dbmanager] < 2.80.8
unknown
[en] The WP-DBManager WordPress plugin before 2.80.8 does not prevent administrators from running arbitrary commands on the server in multisite installations, where only super-administrators should.
- Affected:
- up to 2.80.8
- Fixed in:
- 2.80.8
- Disclosed:
- Aug 15, 2022
CVE-2022-2354 on NVD →
WP-DBManager <= 2.80.7 - Authenticated (Admin+) Remote Code Execution on Multi-Site
high
The WP-DBManager plugin for WordPress is vulnerable to remote code execution due to an incorrect capability check in the ~/database-backup.php file in versions up to, and including, 2.80.7. This makes it possible for high level authenticated users, such as administrators, to run arbitrary commands on the affected serve...
- CVSS:
- 7.2
- Affected:
- up to 2.80.7
- Fixed in:
- 2.80.8
- Disclosed:
- Jul 25, 2022
CVE-2022-2354 on NVD →
WP-DBManager [wp-dbmanager] < 2.79.2
unknown
Arbitrary File Deletion vulnerability found by RIPS in WordPress WP-DBManager plugin (versions <= 2.79.1).
- Affected:
- up to 2.79.2
- Fixed in:
- 2.79.2
- Disclosed:
- Nov 27, 2018
WP-DBManager <= 2.79.1 - Directory Traversal Allowing Arbitrary File Deletion
high
The WP-DBManager plugin for WordPress is vulnerable to Directory Traversal allowing arbitrary file deletion in versions up to, and including, 2.79.1. This allows authenticated high-privilege attackers to delete arbitrary files, which can be used to reset a site and gain administrative access.
- CVSS:
- 8.7
- Affected:
- up to 2.79.2
- Fixed in:
- 2.79.2
- Disclosed:
- Oct 22, 2018
WP-DBManager [wp-dbmanager] < 2.79.2
unknown
The WP-DBManager plugin for WordPress is vulnerable to Directory Traversal allowing arbitrary file deletion in versions up to, and including, 2.79.1. This allows authenticated high-privilege attackers to delete arbitrary files, which can be used to reset a site and gain administrative access.
- Affected:
- up to 2.79.2
- Fixed in:
- 2.79.2
- Disclosed:
- Oct 22, 2018
WP-DBManager [wp-dbmanager] < 2.72
unknown
[en] (1) wp-dbmanager.php and (2) database-manage.php in the WP-DBManager (aka Database Manager) plugin before 2.7.2 for WordPress place credentials on the mysqldump command line, which allows local users to obtain sensitive information by listing the process.
- Affected:
- up to 2.72
- Fixed in:
- 2.72
- Disclosed:
- Jan 5, 2018
CVE-2014-8335 on NVD →
WP-DBManager [wp-dbmanager] < 2.7.2
unknown
[en] The "Sql Run Query" panel in WP-DBManager (aka Database Manager) plugin before 2.7.2 for WordPress allows remote attackers to read arbitrary files by leveraging failure to sufficiently limit queries, as demonstrated by use of LOAD_FILE in an INSERT statement.
- Affected:
- up to 2.7.2
- Fixed in:
- 2.7.2
- Disclosed:
- Jan 5, 2018
CVE-2014-8336 on NVD →
WP-DBManager [wp-dbmanager] < 2.72
unknown
[en] The WP-DBManager (aka Database Manager) plugin before 2.7.2 for WordPress allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) $backup['filepath'] (aka "Path to Backup:" field) or (2) $backup['mysqldumppath'] variable.
- Affected:
- up to 2.72
- Fixed in:
- 2.72
- Disclosed:
- Oct 31, 2014
CVE-2014-8334 on NVD →
WP-DBManager < 2.72 - Command Injection
high
(1) wp-dbmanager.php and (2) database-manage.php in the WP-DBManager (aka Database Manager) plugin before 2.72 for WordPress place credentials on the mysqldump command line, which allows local users to obtain sensitive information by listing the process.
- CVSS:
- 8.8
- Affected:
- up to 2.72
- Fixed in:
- 2.72
- Disclosed:
- Oct 13, 2014
CVE-2014-8335 on NVD →
WP-DBManager < 2.72 - OS Command Injection
high
The WP-DBManager (aka Database Manager) plugin before 2.72 for WordPress allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) $backup['filepath'] (aka "Path to Backup:" field) or (2) $backup['mysqldumppath'] variable.
- CVSS:
- 7.8
- Affected:
- up to 2.72
- Fixed in:
- 2.72
- Disclosed:
- Oct 13, 2014
CVE-2014-8334 on NVD →
WP DB Manager < 2.7.2 - Arbitrary File Read
medium
The "Sql Run Query" panel in WP-DBManager (aka Database Manager) plugin before 2.7.2 for WordPress allows remote attackers to read arbitrary files by leveraging failure to sufficiently limit queries, as demonstrated by use of LOAD_FILE in an INSERT statement.
- CVSS:
- 6.5
- Affected:
- up to 2.7.2
- Fixed in:
- 2.7.2
- Disclosed:
- Oct 13, 2014
CVE-2014-8336 on NVD →
WP-DBManager [wp-dbmanager] < 2.79.2
unknown
The WP-DBManager WordPress plugin was affected by an Arbitrary File Delete security vulnerability.
- Affected:
- up to 2.79.2
- Fixed in:
- 2.79.2
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database