Optimize Database after Deleting Revisions, 1bf13d2a-9492-4f90-9ece-e5da5b132476
- CVE, Research URL
- Application
- Published on
- -
- Research Description
- Optimize Database after Deleting Revisions [rvg-optimize-database] < 5.1 Optimize Database after Deleting Revisions < 5.1 - Missing Authorization via 'odb_csv_download' The Optimize Database after Deleting Revisions plugin for WordPress is vulnerable to information disclosure in versions up to, and including, 5.0.110. This is due to a missing capability check on the 'odb_csv_download' function which is hooked via admin_init. This makes it possible for unauthenticated attackers to trigger a download of the plugin's data.
- Affected versions
-
max 5.1.
- Status
-
vulnerable