Plugin Vulnerability Hub
Plugin 8 known issues Latest disclosed Oct 30, 2025

Advanced Database Cleaner – Optimize & Clean Database to Speed Up Site Performance Vulnerabilities

Review known vulnerability records for the WordPress plugin Advanced Database Cleaner – Optimize & Clean Database to Speed Up Site Performance (`advanced-database-cleaner`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2025-64357, CVE-2025-11497 and CVE-2024-0668, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
8
High or Critical
2
Patch Coverage
100%
Last Updated
Dec 20, 2025
Related Security Guides

Use these guides while reviewing Advanced Database Cleaner – Optimize & Clean Database to Speed Up Site Performance fixes

Pair this plugin vulnerability hub with practical WordPress hardening, scanner, and patch workflow guidance.

Patch Decision Workflow

How to prioritize Advanced Database Cleaner – Optimize & Clean Database to Speed Up Site Performance remediation

Use the hub as a decision layer before opening individual records: confirm whether the issue has a CVE, whether a fixed version exists, and whether the affected range overlaps production installs.

Search-Ready Records
6
1. Match the Package
Confirm the installed WordPress plugin slug is advanced-database-cleaner before acting on any CVE from this cluster.
2. Sort by Severity
Start with 2 high or critical records, then review medium and unrated findings with public references.
3. Check Patch Evidence
8 records include a patch path; verify compatibility before closing the finding.
4. Monitor Gaps
0 records still lack a listed fixed release, so keep this hub in the review queue.
Priority CVE Quick Links

Fast paths into Advanced Database Cleaner – Optimize & Clean Database to Speed Up Site Performance CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
8
Tracked CVE Issue Type Affected Versions Fixed Version CVSS
CVE-2023-49764
Advanced Database Cleaner <= 3.1.2 - Authenticated (Administrator+) SQL Injection
SQL Injection Versions up to 3.1.2 3.1.3 CVSS 7.2
CVE-2021-24141
Advanced Database Cleaner <= 3.0.1 - SQL injection
SQL Injection Versions before 3.0.2 3.0.2 CVSS 7.2
CVE-2024-0668
Advanced Database Cleaner <= 3.1.3 - Authenticated(Administrator+) PHP Object Inject...
Vulnerability Versions up to 3.1.3 3.1.4 CVSS 6.6
CVE-2022-2173
Advanced Database Cleaner <= 3.1.0 - Reflected Cross-Site Scripting
Cross-Site Scripting Versions up to 3.1.0 3.1.1 CVSS 6.1
CVE-2021-24921
Advanced Database Cleaner <= 3.0.3 - Reflected Cross-Site Scripting
Cross-Site Scripting Versions before 3.0.4 3.0.4 CVSS 6.1
CVE-2025-64357
Advanced Database Cleaner <= 3.1.6 - Cross-Site Request Forgery
Cross-Site Request Forgery Versions up to 3.1.6 3.1.7 CVSS 4.3
CVE-2025-11497
Advanced Database Cleaner <= 3.1.6 - Cross-Site Request Forgery to Settings Manipula...
Cross-Site Request Forgery Versions up to 3.1.6 3.1.7 CVSS 4.3
CVE-2022-46813
Advanced Database Cleaner <= 3.1.1 - Cross-Site Request Forgery via aDBc_save_settin...
Cross-Site Request Forgery Versions up to 3.1.1 3.1.2 CVSS 4.3
CVE-2023-49764 High 3.1.3
CVE-2023-49764 Advanced Database Cleaner – Optimize & Clean Database to Speed Up Site Performance SQL Injection

Advanced Database Cleaner <= 3.1.2 - Authenticated (Administrator+) SQL Injection

CVE-2021-24141 High 3.0.2
CVE-2021-24141 Advanced Database Cleaner – Optimize & Clean Database to Speed Up Site Performance SQL Injection

Advanced Database Cleaner <= 3.0.1 - SQL injection

CVE-2024-0668 Medium 3.1.4
CVE-2024-0668 Advanced Database Cleaner – Optimize & Clean Database to Speed Up Site Performance Vulnerability

Advanced Database Cleaner <= 3.1.3 - Authenticated(Administrator+) PHP Object Injection via process_bulk_action

CVE-2022-2173 Medium 3.1.1
CVE-2022-2173 Advanced Database Cleaner – Optimize & Clean Database to Speed Up Site Performance Cross-Site Scripting

Advanced Database Cleaner <= 3.1.0 - Reflected Cross-Site Scripting

CVE-2021-24921 Medium 3.0.4
CVE-2021-24921 Advanced Database Cleaner – Optimize & Clean Database to Speed Up Site Performance Cross-Site Scripting

Advanced Database Cleaner <= 3.0.3 - Reflected Cross-Site Scripting

CVE-2025-64357 Medium 3.1.7
CVE-2025-64357 Advanced Database Cleaner – Optimize & Clean Database to Speed Up Site Performance Cross-Site Request Forgery

Advanced Database Cleaner <= 3.1.6 - Cross-Site Request Forgery

CVE-2025-11497 Medium 3.1.7
CVE-2025-11497 Advanced Database Cleaner – Optimize & Clean Database to Speed Up Site Performance Cross-Site Request Forgery

Advanced Database Cleaner <= 3.1.6 - Cross-Site Request Forgery to Settings Manipulation

CVE-2022-46813 Medium 3.1.2
CVE-2022-46813 Advanced Database Cleaner – Optimize & Clean Database to Speed Up Site Performance Cross-Site Request Forgery

Advanced Database Cleaner <= 3.1.1 - Cross-Site Request Forgery via aDBc_save_settings_callback

Coverage Snapshot

What this page helps you verify fast

This hub clusters tracked records for Advanced Database Cleaner – Optimize & Clean Database to Speed Up Site Performance so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
8 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
0 critical and 2 high severity findings.
Recent CVEs
CVE-2025-64357, CVE-2025-11497 and CVE-2024-0668
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

Known Vulnerabilities

Reports for Advanced Database Cleaner – Optimize & Clean Database to Speed Up Site Performance

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes CVE-2025-64357
CVE-2025-64357: Advanced Database Cleaner <= 3.1.6 - Cross-Site Request Forgery

The Advanced Database Cleaner – Optimize & Clean Database to Speed Up Site Performance plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.6. This is due to missing or incorrect nonce validation on a function. This makes it p...

Published
Oct 30, 2025
Patched Release
3.1.7
Affected Versions
Versions up to 3.1.6
Next Step
Update to 3.1.7 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-11497
CVE-2025-11497: Advanced Database Cleaner <= 3.1.6 - Cross-Site Request Forgery to Settings Manipulation

The Advanced Database Cleaner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.6. This is due to missing or incorrect nonce validation on the aDBc_prepare_elements_to_clean() function. This makes it possible for unauthenti...

Published
Oct 24, 2025
Patched Release
3.1.7
Affected Versions
Versions up to 3.1.6
Next Step
Update to 3.1.7 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-0668
CVE-2024-0668: Advanced Database Cleaner <= 3.1.3 - Authenticated(Administrator+) PHP Object Injection via process_bulk_action

The Advanced Database Cleaner plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.1.3 via deserialization of untrusted input in the 'process_bulk_action' function. This makes it possible for authenticated attacker, with administrator...

Published
Jan 24, 2024
Patched Release
3.1.4
Affected Versions
Versions up to 3.1.3
Next Step
Update to 3.1.4 or newer if supported.
Plugin High Patched: Yes CVE-2023-49764
CVE-2023-49764: Advanced Database Cleaner <= 3.1.2 - Authenticated (Administrator+) SQL Injection

The Advanced Database Cleaner plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in versions up to, and including, 3.1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This mak...

Published
Dec 04, 2023
Patched Release
3.1.3
Affected Versions
Versions up to 3.1.2
Next Step
Update to 3.1.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2022-46813
CVE-2022-46813: Advanced Database Cleaner <= 3.1.1 - Cross-Site Request Forgery via aDBc_save_settings_callback

The Advanced Database Cleaner plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1.1. This is due to missing or incorrect nonce validation on the aDBc_save_settings_callback function. This makes it possible for unauthenticated att...

Published
Feb 21, 2023
Patched Release
3.1.2
Affected Versions
Versions up to 3.1.1
Next Step
Update to 3.1.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2022-2173
CVE-2022-2173: Advanced Database Cleaner <= 3.1.0 - Reflected Cross-Site Scripting

The Advanced Database Cleaner WordPress plugin before 3.1.1 does not escape numerous generated URLs before outputting them back in href attributes of admin dashboard pages, leading to Reflected Cross-Site Scripting

Published
Jun 27, 2022
Patched Release
3.1.1
Affected Versions
Versions up to 3.1.0
Next Step
Update to 3.1.1 or newer if supported.
Plugin Medium Patched: Yes CVE-2021-24921
CVE-2021-24921: Advanced Database Cleaner <= 3.0.3 - Reflected Cross-Site Scripting

The Advanced Database Cleaner WordPress plugin before 3.0.4 does not sanitise and escape $_GET keys and values before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues

Published
Jan 24, 2022
Patched Release
3.0.4
Affected Versions
Versions before 3.0.4
Next Step
Update to 3.0.4 or newer if supported.
Plugin High Patched: Yes CVE-2021-24141
CVE-2021-24141: Advanced Database Cleaner <= 3.0.1 - SQL injection

Unvaludated input in the Advanced Database Cleaner plugin, versions before 3.0.2, lead to SQL injection allowing high privilege users (admin+) to perform SQL attacks.

Published
Sep 06, 2020
Patched Release
3.0.2
Affected Versions
Versions before 3.0.2
Next Step
Update to 3.0.2 or newer if supported.