cleantalk
Vulnerabilities and Security Researches

Optimize Database after Deleting Revisions, 1bf13d2a-9492-4f90-9ece-e5da5b132476

Published on
-
Research Description
Optimize Database after Deleting Revisions [rvg-optimize-database] < 5.1 Optimize Database after Deleting Revisions &lt; 5.1 - Missing Authorization via &#039;odb_csv_download&#039; The Optimize Database after Deleting Revisions plugin for WordPress is vulnerable to information disclosure in versions up to, and including, 5.0.110. This is due to a missing capability check on the &#039;odb_csv_download&#039; function which is hooked via admin_init. This makes it possible for unauthenticated attackers to trigger a download of the plugin&#039;s data.
Affected versions
max 5.1.
Status
vulnerable