Executive brief
CleanTalk's WordPress security plugin, which scans sites for malware and security threats, contains an unauthenticated SQL injection vulnerability that allows attackers to directly access the website's database without needing credentials. An attacker exploiting this flaw could read, modify, or delete all website data—including user accounts, customer information, and private content—potentially exposing sensitive data and disrupting site operations.
Technical details
The vulnerability is an unauthenticated SQL injection flaw in the Security & Malware Scan plugin version 2.184 and earlier. The injection point is directly accessible over the network without authentication, allowing an attacker to craft malicious SQL queries and execute arbitrary database operations. An attacker can leverage this to extract user credentials, customer data, and other sensitive information stored in the WordPress database, or to modify/delete records. The vulnerability has been patched in version 2.185; users should update immediately.
Affected products
- CleanTalk Security & Malware Scan <=2.184
Timeline
- 2026-08-20: disclosed
- 2026-08-19: patched: Version 2.185 released with patch