Unauthenticated SQL Injection in CleanTalk Security & Malware Scan Plugin
CVE-2026-66593
9.3CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 20 August 2026
What is CVE-2026-66593?
An unauthenticated SQL Injection vulnerability has been identified in the Security & Malware scan plugin developed by CleanTalk for WordPress. This issue affects versions up to 2.184, allowing attackers to execute arbitrary SQL commands without authentication. Proper input validation is essential to mitigate potential data breaches and unauthorized access. Users are strongly advised to upgrade to the latest version to protect their websites.
Affected Version(s)
Security & Malware scan by CleanTalk <= 2.184