WP-DBManager < 2.80.8 - Admin+ Remote Command Execution
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 1.0%
exploitation probability
1.0%top 39% of all CVEs
observed exploitation
nono source reports it
The WP-DBManager WordPress plugin before 2.80.8 does not prevent administrators from running arbitrary commands on the server in multisite installations, where only super-administrators should.
Affected products
Unknown · WP-DBManager