ARI-Adminer <= 1.1.14 - Missing Authorization and No Direct File Access Restrictions

Missing Authorization
CVE CVE-2019-25215
CVSS High (7.3)
Publicly Published April 8, 2019
Last Updated October 16, 2024
Description

The ARI-Adminer plugin for WordPress is vulnerable to authorization bypass due to a lack of file access controls in nearly every file of the plugin in versions up to, and including, 1.1.14. This makes it possible for unauthenticated attackers to call the files directly and perform a wide variety of unauthorized actions such as accessing a site's database and making changes.

References

1 affected software package

Software Type Plugin
Software Slug ari-adminer (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.1.14
Patched Version
  • 1.1.15
This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.
License: Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy. License Detail.