PT-2025-43720 · WordPress · Advanced Database Cleaner

Published

2025-10-25

·

Updated

2025-10-25

·

CVE-2025-11497

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Advanced Database Cleaner plugin for WordPress versions up to and including 3.1.6
Description The Advanced Database Cleaner plugin for WordPress is susceptible to a Cross-Site Request Forgery (CSRF) issue. This is caused by insufficient or incorrect nonce validation within the aDBc prepare elements to clean() function. An unauthenticated attacker could potentially modify the 'keep last' setting by crafting a malicious request and tricking a site administrator into triggering an action, such as clicking a link.
Recommendations Update the Advanced Database Cleaner plugin to a version newer than 3.1.6.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-11497

Affected Products

Advanced Database Cleaner