PT-2026-42104 · WordPress · Advanced Database Cleaner – Premium

Published

2026-05-20

·

Updated

2026-05-20

·

CVE-2026-7522

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Advanced Database Cleaner – Premium versions prior to 4.1.1
Description The Advanced Database Cleaner – Premium plugin for WordPress contains a Local File Inclusion issue, which occurs when an application includes a file without properly validating the input, allowing an attacker to read or execute files on the server. Authenticated attackers with Subscriber-level access or higher can use the template parameter to include and execute arbitrary .php files. This can lead to the bypass of access controls, unauthorized access to sensitive data, or remote code execution if .php files can be uploaded to the server.
Recommendations Update the plugin to a version later than 4.1.0. As a temporary workaround, restrict access to the template parameter to minimize the risk of exploitation.

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-7522

Affected Products

Advanced Database Cleaner – Premium