Sigmaplugin develops WordPress-focused administrative plugins, particularly database-maintenance and site-reset utilities that operate with elevated privileges within WordPress installations. The vendor's vulnerability exposure centers on application-layer input-handling and state-management weaknesses, including cross-site scripting, SQL injection, cross-site request forgery, and unsafe deserialization, which recur across its product line and reflect the trust boundary challenges inherent to WordPress plugins with administrative scope. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sigmaplugin over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-46813HIGH Cross-Site Request Forgery (CSRF) vulnerability in Younes JFR. Advanced Database Cleaner plugin <= 3.1.1 versions. | May 23, 2023 | 8.8 | 27 | NO | NO |
CVE-2021-24141HIGH Unvaludated input in the Advanced Database Cleaner plugin, versions before 3.0.2, lead to SQL injection allowing high privilege users (admin+) to perform SQL attacks. | Mar 18, 2021 | 7.2 | 23 | NO | NO |
CVE-2022-2181MEDIUM The Advanced WordPress Reset WordPress plugin before 1.6 does not escape some generated URLs before outputting them back in href attributes of admin dashboard pages, leading to Ref | Aug 1, 2022 | 6.1 | 22 | NO | NO |
CVE-2022-2173MEDIUM The Advanced Database Cleaner WordPress plugin before 3.1.1 does not escape numerous generated URLs before outputting them back in href attributes of admin dashboard pages, leading | Jul 17, 2022 | 6.1 | 22 | NO | NO |
CVE-2024-0668HIGH The Advanced Database Cleaner plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.1.3 via deserialization of untrusted input in the ' | Feb 5, 2024 | 7.2 | 21 | NO | NO |
CVE-2023-49764HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Younes JFR. Advanced Database Cleaner.This issue affects Advanced Database Cle | Dec 19, 2023 | 7.2 | 21 | NO | NO |
CVE-2021-24921MEDIUM The Advanced Database Cleaner WordPress plugin before 3.0.4 does not sanitise and escape $_GET keys and values before outputting them back in attributes, leading to Reflected Cross | Feb 21, 2022 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sigmaplugin.
Media articles that mention a CVE ID that affects a product developed by Sigmaplugin — matched by CVE ID, not by vendor name.