CVE Database /
CVE-2024-0668
CVE · High
CVE-2024-0668 — Advanced Database Cleaner – Optimize & Clean Database to Speed Up Site Performance [advanced-database-cleaner] < 3.1.4
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-0668
|
Advanced Database Cleaner – Optimize & Clean Database to Speed Up Site Performance [advanced-database-cleaner] < 3.1.4 |
Deserialization of Untrusted Data |
High
7.2
|
< 3.1.4
|
3.1.4 |
2024-01-24 |
—
|
CVE-2024-0668
The Advanced Database Cleaner plugin for WordPress versions up to and including 3.1.3 contains a PHP Object Injection vulnerability in the 'process_bulk_action' function due to improper handling of unserialized user input. An authenticated attacker with administrator-level access or higher can inject malicious PHP objects, though the plugin itself lacks a gadget chain to perform direct attacks. However, if other installed plugins or themes on the same site contain vulnerable code chains, an attacker could exploit this to delete files, access sensitive information, or execute arbitrary code.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings