Unauthenticated CSRF Vulnerability in Garbage Collector Plugin by WordPress
CVE-2026-66686

6.5MEDIUM

What is CVE-2026-66686?

The Garbage Collector (Database Cleanup) plugin for WordPress is susceptible to an unauthenticated Cross Site Request Forgery (CSRF) vulnerability. This flaw exists in versions 0.14 and below, allowing attackers to perform actions on behalf of authenticated users without their consent. Exploiting this vulnerability may lead to unauthorized operations that can compromise the integrity of the website’s data and user interactions.

Affected Version(s)

Plugins Garbage Collector (Database Cleanup) <= 0.14

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ananda Dhakal (Patchstack) | Patchstack Bug Bounty Program
.