Junglewise Threat Intelligence

CVE-2026-66593: CleanTalk Security & Malware Scan SQL injection

CVE-2026-66593 · Severity: critical · CVSS 9.3 · Published 2026-08-20

Vendors: CleanTalk.

Executive brief

CleanTalk's WordPress security plugin, which scans sites for malware and security threats, contains an unauthenticated SQL injection vulnerability that allows attackers to directly access the website's database without needing credentials. An attacker exploiting this flaw could read, modify, or delete all website data—including user accounts, customer information, and private content—potentially exposing sensitive data and disrupting site operations.

Technical details

The vulnerability is an unauthenticated SQL injection flaw in the Security & Malware Scan plugin version 2.184 and earlier. The injection point is directly accessible over the network without authentication, allowing an attacker to craft malicious SQL queries and execute arbitrary database operations. An attacker can leverage this to extract user credentials, customer data, and other sensitive information stored in the WordPress database, or to modify/delete records. The vulnerability has been patched in version 2.185; users should update immediately.

Affected products

  • CleanTalk Security & Malware Scan <=2.184

Timeline

  • 2026-08-20: disclosed
  • 2026-08-19: patched: Version 2.185 released with patch

References