Vulnerabilities and security researches foradvanced-database-cleaner advanced-database-cleaner
Direction: ascendingJun 07, 2024
Advanced Database Cleaner # CVE-2021-24141
- CVE, Research URL
- Home page URL
- Application
- Date
- Mar 18, 2021
- Research Description
- Unvaludated input in the Advanced Database Cleaner plugin, versions before 3.0.2, lead to SQL injection allowing high privilege users (admin+) to perform SQL attacks.
- Affected versions
-
max 3.0.2.
- Status
-
vulnerable
Advanced Database Cleaner # CVE-2023-49764
- CVE, Research URL
- Home page URL
- Application
- Date
- Dec 20, 2023
- Research Description
- Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Younes JFR. Advanced Database Cleaner.This issue affects Advanced Database Cleaner: from n/a through 3.1.2.
- Affected versions
-
max 3.1.3.
- Status
-
vulnerable
Advanced Database Cleaner # CVE-2022-2173
- CVE, Research URL
- Home page URL
- Application
- Date
- Jul 17, 2022
- Research Description
- The Advanced Database Cleaner WordPress plugin before 3.1.1 does not escape numerous generated URLs before outputting them back in href attributes of admin dashboard pages, leading to Reflected Cross-Site Scripting
- Affected versions
-
max 3.1.1.
- Status
-
vulnerable
Advanced Database Cleaner # CVE-2022-46813
- CVE, Research URL
- Home page URL
- Application
- Date
- May 23, 2023
- Research Description
- Cross-Site Request Forgery (CSRF) vulnerability in Younes JFR. Advanced Database Cleaner plugin <= 3.1.1 versions.
- Affected versions
-
max 3.1.2.
- Status
-
vulnerable
Advanced Database Cleaner # CVE-2024-0668
- CVE, Research URL
- Home page URL
- Application
- Date
- Feb 06, 2024
- Research Description
- The Advanced Database Cleaner plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.1.3 via deserialization of untrusted input in the 'process_bulk_action' function. This makes it possible for authenticated attacker, with administrator access and above, to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.
- Affected versions
-
max 3.1.4.
- Status
-
vulnerable
Advanced Database Cleaner # CVE-2021-24921
- CVE, Research URL
- Home page URL
- Application
- Date
- Feb 21, 2022
- Research Description
- The Advanced Database Cleaner WordPress plugin before 3.0.4 does not sanitise and escape $_GET keys and values before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues
- Affected versions
-
max 3.0.4.
- Status
-
vulnerable
Nov 10, 2025
Advanced Database Cleaner # CVE-2025-11497
- CVE, Research URL
- Home page URL
- Application
- Date
- Oct 25, 2025
- Research Description
- The Advanced Database Cleaner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.6. This is due to missing or incorrect nonce validation on the aDBc_prepare_elements_to_clean() function. This makes it possible for unauthenticated attackers to alter the keep last setting via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
- Affected versions
-
max 3.1.7.
- Status
-
vulnerable