Unrated severityNVD Advisory· Published Oct 31, 2014· Updated May 6, 2026
CVE-2014-8334
CVE-2014-8334
Description
The WP-DBManager (aka Database Manager) plugin before 2.7.2 for WordPress allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) $backup['filepath'] (aka "Path to Backup:" field) or (2) $backup['mysqldumppath'] variable.
Affected products
1- cpe:2.3:a:wp-dbmanager_project:wp-dbmanager:*:*:*:*:*:wordpress:*:*Range: <=2.71
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- wordpress.org/plugins/wp-dbmanager/changelog/nvdPatch
- packetstormsecurity.com/files/128785/WordPress-Database-Manager-2.7.1-Command-Injection-Credential-Leak.htmlnvdExploit
- seclists.org/fulldisclosure/2014/Oct/99nvdExploit
- seclists.org/oss-sec/2014/q4/365nvdExploit
- seclists.org/oss-sec/2014/q4/410nvdExploit
- www.vapid.dhs.org/advisories/wordpress/plugins/wp-dbmanager-2.7.1/index.htmlnvdExploit
- osvdb.org/show/osvdb/113508nvd
- www.securityfocus.com/archive/1/533763/100/0/threadednvd
- www.securityfocus.com/bid/70626nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/97689nvd
News mentions
0No linked articles in our index yet.