Description
WordPress Plugin Adminer is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently authenticate/connect to the local/internal WordPress databases from the public internet. WordPress Plugin Adminer version 1.4.5 is vulnerable; prior versions may also be affected.
Remediation
Disable the plugin until a fix is available
References
https://sumofpwn.nl/advisory/2016/wordpress_adminer_plugin_allows_public__local__database_login.html
http://www.openwall.com/lists/oss-security/2017/03/01/5
https://packetstormsecurity.com/files/141423/WordPress-Adminer-1.4.4-Interface-Exposure.html
Related Vulnerabilities
WordPress Plugin Simple Feature Requests Free Unspecified Vulnerability (1.0.4)
WordPress Plugin WordPress Mobile Pack Information Disclosure (2.0.1)
WordPress Plugin Clever Addons for Elementor Multiple Cross-Site Scripting Vulnerabilities (2.0.15)
WordPress Plugin GeSHi Source Colorer Cross-Site Scripting (0.13)