Description
WordPress Plugin Adminer is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently authenticate/connect to the local/internal WordPress databases from the public internet. WordPress Plugin Adminer version 1.4.5 is vulnerable; prior versions may also be affected.
Remediation
Disable the plugin until a fix is available
References
https://sumofpwn.nl/advisory/2016/wordpress_adminer_plugin_allows_public__local__database_login.html
http://www.openwall.com/lists/oss-security/2017/03/01/5
https://packetstormsecurity.com/files/141423/WordPress-Adminer-1.4.4-Interface-Exposure.html
Related Vulnerabilities
MySQL CVE-2022-21264 Vulnerability (CVE-2022-21264)
IBM RTC Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-6024)
WordPress Plugin SpiderCatalog SQL Injection (1.7.3)
WordPress Plugin WP Cost Estimation & Payment Forms Builder Multiple Vulnerabilities (9.642)
Apache Tomcat Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2013-6357)