Critical SQL Injection Vulnerability in CleanTalk Security Plugin

Critical SQL Injection Vulnerability in CleanTalk Security Plugin

First seen 20 Aug 2026, 21:54 UTC Feedlyradar.offseq.comeuvd.enisa.europa.euvuldb.com 88% similarity 72.0

Article Content

Browse articles
ThreatCluster

A severe SQL injection vulnerability (CVE-2026-66593) has been identified in CleanTalk's Security & Malware scan plugin, affecting versions up to 2.184. This unauthenticated vulnerability allows attackers to inject malicious SQL commands remotely, potentially exposing sensitive data and causing service disruptions. The CVSS score for this vulnerability is 9.3, indicating a high level of severity. No known exploits have been reported yet, but a patch has been released on the same day as the CVE publication. Users are advised to upgrade to a version later than 2.184 and implement security measures like input validation and Web Application Firewalls. The vulnerability was disclosed on August 20, 2026, with no vendor advisory available prior to the patch release.

Key Points: • CVE-2026-66593 is a critical SQL injection vulnerability in CleanTalk plugin versions <= 2.184. • Attackers can exploit this flaw remotely without authentication, risking sensitive data exposure. • A patch is available as of August 20, 2026; users must upgrade immediately to mitigate risks.

ThreatCluster AI How this analysis works

Timeline

2026-08-20
CVE-2026-66593 published
CleanTalk disclosed a critical SQL injection vulnerability affecting versions up to 2.184.
radar.offseq.com
2026-08-20
Patch released
A patch for the SQL injection vulnerability was released, urging users to upgrade to versions later than 2.184.
Feedly

Community

Browse all →