CVE-2026-7522
8.8SigmaPlugin · Advanced Database Cleaner – Premium
The Advanced Database Cleaner – Premium plugin for WordPress is vulnerable to Local File Inclusion, allowing attackers to manipulate file inclusion paths.
Executive summary
A critical Local File Inclusion (LFI) vulnerability in the Advanced Database Cleaner – Premium plugin for WordPress could allow authenticated attackers to achieve remote code execution.
Vulnerability
The plugin contains a flaw in file handling (CWE-98) that permits an authenticated attacker with low privileges to include arbitrary files, potentially leading to unauthorized system access.
Business impact
Successful exploitation of this vulnerability allows an attacker to read sensitive files or execute arbitrary code on the server hosting the WordPress instance. Given the CVSS score of 8.8, this poses a significant risk to data confidentiality, integrity, and availability, potentially leading to full site compromise.
Remediation
Immediate Action: Update the "Advanced Database Cleaner – Premium" plugin to version 4.1.1 or later immediately.
Proactive Monitoring: Review web server access and error logs for suspicious file inclusion requests or unexpected PHP execution patterns.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block common LFI patterns and directory traversal attempts.
Exploitation status
Public Exploit Available: No confirmed public exploit available.
Analyst recommendation
The severity of this vulnerability necessitates immediate action. Administrators should verify their plugin version and apply the 4.1.1 update as the primary defense against potential exploitation.