WP-DBManager
Explore WP-DBManager vulnerabilities across all versions. Currently tracking 5 known vulnerabilities, including severity, impact, and patch status.
Vulnerability Records

WP-DBManager
Author
Lester Chan
Allows you to optimize database, repair database, backup database, restore database, delete backup database , drop/empty tables and run selected queries. Supports automatic scheduling of backing up, optimizing and repairing of database. General Usage Activate WP-DBManager Plugin The script will automatically create a folder called backup-db in the wp-content folder if that folder is writable. If it is not created, please create the folder and ensure that the folder is writable Go to WP-Admin -> Database -> DB Options to configure the database options Secure the backup folder, see below Go to WP-Admin -> Database -> Backup DB, which checks whether the folder is actually reachable over HTTP and tells you if it is Securing The Backup Folder A database backup contains everything, including your users table. Anyone who can guess a backup file name can download the lot, so the folder must not be served over HTTP. The reliable option, on any server: set Path To Backup under WP-Admin -> Database -> DB Options to a folder outside your web root, for example /var/www/example.com/backup-db when WordPress lives in /var/www/example.com/public_html. Nothing served, nothing to configure. If the folder has to stay inside the web root: Apache — move htaccess.txt from Folder: wp-content/plugins/wp-dbmanager to Folder: wp-content/backup-db/.htaccess IIS — move Web.config.txt from Folder: wp-content/plugins/wp-dbmanager to Folder: wp-content/backup-db/Web.config nginx — nginx does not read .htaccess files, so the file above does nothing. Add this to your server block and reload nginx: location ^~ /wp-content/backup-db/ { deny all; } Move index.php from Folder: wp-content/plugins/wp-dbmanager to Folder: wp-content/backup-db/index.php as well, so the folder cannot be listed. The Backup DB page requests a file from the folder and reports what the server actually returns, so you can confirm the folder is closed rather than assume it. Development https://github.com/lesterchan/wp-dbmanager Credits Plugin icon by Freepik from Flaticon Donations I spent most of my free time creating, updating, maintaining and supporting these plugins, if you really love my plugins and could spare me a couple of bucks, I will really appreciate it. If not feel free to use it without any obligations.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C