CVE-2026-66593: WordPress Security & Malware scan by CleanTalk plugin <= 2.184 - SQL Injection vulnerability
Published Aug 20, 2026
·Updated
Unauthenticated SQL Injection in Security & Malware scan by CleanTalk <= 2.184 versions.
Affected Software
1 affected component
wordpress/clean-talk-security-malware-scan<=2.184
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Security & Malware scan by CleanTalk pluginto a version that resolves this vulnerability.Fixed in 2.185
Event History
Aug 20, 2026
CVE Published
via MITRE·12:07 PM
Data Sourced
via MITRE·12:07 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or other prior privileges to attempt exploitation over the network.
2
Which installations are affected?
Installations using the Security & Malware scan by CleanTalk WordPress plugin at version 2.184 or earlier are affected.
3
What is the potential impact?
The supplied severity vector indicates high confidentiality impact and low availability impact, with no integrity impact specified. The scope is marked as changed.