CVE · High

CVE-2024-0668 — Advanced Database Cleaner – Optimize & Clean Database to Speed Up Site Performance [advanced-database-cleaner] < 3.1.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-0668 Advanced Database Cleaner – Optimize & Clean Database to Speed Up Site Performance [advanced-database-cleaner] < 3.1.4 Deserialization of Untrusted Data High 7.2 < 3.1.4 3.1.4 2024-01-24

CVE-2024-0668

The Advanced Database Cleaner plugin for WordPress versions up to and including 3.1.3 contains a PHP Object Injection vulnerability in the 'process_bulk_action' function due to improper handling of unserialized user input. An authenticated attacker with administrator-level access or higher can inject malicious PHP objects, though the plugin itself lacks a gadget chain to perform direct attacks. However, if other installed plugins or themes on the same site contain vulnerable code chains, an attacker could exploit this to delete files, access sensitive information, or execute arbitrary code.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.