Beta

Report

Database Cleaner <= 0.9.8 is vulnerable to Sensitive Data Exposure via Log File vulnerability

Unauthenticated
Published
2023-12-26

The Database Cleaner: Clean, Optimize & Repair plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 0.9.8 via the plugin's log file. This makes it possible for unauthenticated attackers to extract sensitive data including system and plugin configuration.

CVSS

Score:5.3

Severity:Medium

Version: 0.9.8

There is a patch available in v0.9.9 and we strongly recommend you update to this version as soon as possible.