The WP-DBManager WordPress plugin before 2.80.8 does not...
High severity
Unreviewed
Published
Aug 16, 2022
to the GitHub Advisory Database
•
Updated Jun 27, 2023
Description
Published by the National Vulnerability Database
Aug 15, 2022
Published to the GitHub Advisory Database
Aug 16, 2022
Last updated
Jun 27, 2023
The WP-DBManager WordPress plugin before 2.80.8 does not prevent administrators from running arbitrary commands on the server in multisite installations, where only super-administrators should.
References