Beta

Report

Advanced Database Cleaner PRO <= 3.2.10 is vulnerable to Limited .txt Path Traversal vulnerability

Subscriber
Published
2025-05-21

The advanced-database-cleaner-pro plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 3.2.10. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform actions on .txt files outside of the originally intended directory.

CVSS

Score:6.4

Severity:Medium

Version: 3.2.10

There is a patch available in v3.2.11 and we strongly recommend you update to this version as soon as possible.