Unauthenticated CSRF Vulnerability in Garbage Collector Plugin by WordPress
CVE-2026-66686
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 6 August 2026
What is CVE-2026-66686?
The Garbage Collector (Database Cleanup) plugin for WordPress is susceptible to an unauthenticated Cross Site Request Forgery (CSRF) vulnerability. This flaw exists in versions 0.14 and below, allowing attackers to perform actions on behalf of authenticated users without their consent. Exploiting this vulnerability may lead to unauthorized operations that can compromise the integrity of the website’s data and user interactions.
Affected Version(s)
Plugins Garbage Collector (Database Cleanup) <= 0.14
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Ananda Dhakal (Patchstack) | Patchstack Bug Bounty Program