Description
Path Traversal: '.../...//' vulnerability in SigmaPlugin Advanced Database Cleaner PRO allows Path Traversal.This issue affects Advanced Database Cleaner PRO: from n/a through 3.2.10.
Published: 2026-01-07
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper sanitization of .txt file paths in the Advanced Database Cleaner PRO WordPress plugin allows path traversal using the form ".../...//". The flaw can enable an attacker to read arbitrary files on the server that match the .txt extension, potentially revealing sensitive configuration data or credentials. The CVSS score of 6.4 indicates a medium severity vulnerability, primarily impacting confidentiality but not directly affecting integrity or availability.

Affected Systems

The vulnerability affects the SigmaPlugin Advanced Database Cleaner PRO for WordPress, versions from the earliest available release through 3.2.10.

Risk and Exploitability

The EPSS score of < 1% signals that exploitation is currently rare, and the CVSS score of 6.4 confirms a medium severity vulnerability. The likely attack vector involves a user with access to the plugin’s interface or a remote request to the plugin’s endpoint that processes .txt files, allowing an attacker to read arbitrary .txt files on the server and potentially disclose sensitive configuration information. The vulnerability is not listed in the CISA KEV catalog and therefore does not have a known active exploit, but the potential for data exposure warrants timely remediation.

Generated by OpenCVE AI on May 1, 2026 at 05:58 UTC.

Remediation

Vendor Solution

Update the WordPress Advanced Database Cleaner PRO wordpress plugin to the latest available version (at least 3.2.11).


OpenCVE Recommended Actions

  • Update the Advanced Database Cleaner PRO plugin to version 3.2.11 or later.
  • Configure the web server or a .htaccess file to deny HTTP access to .txt files outside designated plugin directories.
  • Implement file system permissions that restrict the web process to read only the necessary plugin files and prevent reading of arbitrary system files.

Generated by OpenCVE AI on May 1, 2026 at 05:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Apr 2026 19:45:00 +0000


Tue, 28 Apr 2026 18:30:00 +0000

Type Values Removed Values Added
Description Path Traversal: '.../...//' vulnerability in SigmaPlugin Advanced Database Cleaner PRO advanced-database-cleaner-pro allows Path Traversal.This issue affects Advanced Database Cleaner PRO: from n/a through <= 3.2.10. Path Traversal: '.../...//' vulnerability in SigmaPlugin Advanced Database Cleaner PRO allows Path Traversal.This issue affects Advanced Database Cleaner PRO: from n/a through 3.2.10.
References

Thu, 23 Apr 2026 15:30:00 +0000


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Description Path Traversal: '.../...//' vulnerability in SigmaPlugin Advanced Database Cleaner PRO allows Path Traversal.This issue affects Advanced Database Cleaner PRO: from n/a through 3.2.10. Path Traversal: '.../...//' vulnerability in SigmaPlugin Advanced Database Cleaner PRO advanced-database-cleaner-pro allows Path Traversal.This issue affects Advanced Database Cleaner PRO: from n/a through <= 3.2.10.
References

Thu, 08 Jan 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Sigmaplugin
Sigmaplugin advanced Database Cleaner
Wordpress
Wordpress wordpress
Vendors & Products Sigmaplugin
Sigmaplugin advanced Database Cleaner
Wordpress
Wordpress wordpress

Wed, 07 Jan 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Jan 2026 12:45:00 +0000

Type Values Removed Values Added
Description Path Traversal: '.../...//' vulnerability in SigmaPlugin Advanced Database Cleaner PRO allows Path Traversal.This issue affects Advanced Database Cleaner PRO: from n/a through 3.2.10.
Title WordPress Advanced Database Cleaner PRO Plugin <= 3.2.10 - Limited .txt Path Traversal vulnerability
Weaknesses CWE-35
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L'}


Subscriptions

Sigmaplugin Advanced Database Cleaner
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:37.074Z

Reserved: 2025-04-22T09:21:51.395Z

Link: CVE-2025-46256

cve-icon Vulnrichment

Updated: 2026-01-07T14:20:20.576Z

cve-icon NVD

Status : Deferred

Published: 2026-01-07T13:15:43.123

Modified: 2026-04-28T19:32:10.800

Link: CVE-2025-46256

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T06:00:13Z

Weaknesses