Executive brief
The Advanced Database Cleaner Premium plugin for WordPress, which is used to optimize and clean up website databases, contains a security flaw. This vulnerability allows users with low-level account access (such as subscribers) to execute malicious code on the server. An attacker could use this to steal sensitive data, bypass security controls, or take full control of the website.
Technical details
The Advanced Database Cleaner – Premium plugin for WordPress is vulnerable to Local File Inclusion (LFI) in versions up to and including 4.1.0. The vulnerability exists due to insufficient validation of the 'template' parameter, allowing authenticated attackers with Subscriber-level permissions or higher to include and execute arbitrary .php files. If an attacker can upload a malicious PHP file through other means, this flaw can be leveraged to achieve full remote code execution (RCE). The issue was addressed in version 4.1.1, which patched the underlying EDD SDK package.
Affected products
- SigmaPlugin Advanced Database Cleaner - Premium up to, and including, 4.1.0
Timeline
- 2026-05-05: patched: Version 4.1.1 released with security fixes.
- 2026-05-20: disclosed: CVE-2026-7522 published.