PT-2025-43720 · WordPress · Advanced Database Cleaner

CVE-2025-11497

·

Published

2025-10-25

·

Updated

2025-10-25

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Advanced Database Cleaner plugin for WordPress versions up to and including 3.1.6
Description The Advanced Database Cleaner plugin for WordPress is susceptible to a Cross-Site Request Forgery (CSRF) issue. This is caused by insufficient or incorrect nonce validation within the aDBc prepare elements to clean() function. An unauthenticated attacker could potentially modify the 'keep last' setting by crafting a malicious request and tricking a site administrator into triggering an action, such as clicking a link.
Recommendations Update the Advanced Database Cleaner plugin to a version newer than 3.1.6.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-11497

Affected Products

Advanced Database Cleaner