The Advanced Database Cleaner – Premium plugin for WordPress contains a Local File Inclusion (LFI) vulnerability in versions up to and including 4.1.0. The flaw exists in the handling of the 'template' parameter, which fails to properly validate or sanitize user-supplied input before using it in file inclusion operations. This allows authenticated attackers with Subscriber-level privileges or higher to in [truncated]
A Path Traversal vulnerability, described as '.../...//' and tracked as CVE-2025-46256, has been identified in the Advanced Database Cleaner PRO plugin affecting versions from n/a through 3.2.10. This issue, with a CVSS score of 6.4, allows for potential unauthorized file access or modification. The vulnerability could enable attackers to access or modify files outside the intended directory structure, po [truncated]