Sceawere

Vulnerability Detail

CVE-2026-66593UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

CleanTalk SQL Injection Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.3
Creation Date
6h ago
Vendor
CleanTalk Inc
Product
Security & Malware scan by CleanTalk
Attack Type
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated SQL Injection in Security & Malware scan by CleanTalk <= 2.184 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.3",
  "pubDate": "2026-08-20T12:16:33.187Z",
  "pubdate": "2026-08-20T12:16:33.187Z",
  "executiveSummary": "An unauthenticated SQL Injection vulnerability has been identified in the Security & Malware scan by CleanTalk plugin, affecting version 2.184 and all prior versions. This security flaw arises from improper sanitization and validation of user-supplied input before it is incorporated into database queries executed by the application.\nSuccessful exploitation of this vulnerability grants an unauthenticated remote attacker the ability to manipulate SQL queries executed against the underlying database. This capability can lead to unauthorized access, extraction of sensitive data such as user credentials and system configurations, data tampering, and potentially complete compromise of the affected WordPress installation.\nThe risk implication is critical due to the lack of authentication requirements, allowing any remote threat actor to interact directly with the vulnerable component over the network without requiring prior system access or privileged accounts. Exploitation requires the vulnerable plugin to be active and accessible to incoming HTTP requests.\nOrganizations utilizing the Security & Malware scan by CleanTalk plugin are at immediate risk if running vulnerable versions. The primary remediation involves updating the software to a patched version beyond 2.184 as soon as updates are made available by the vendor.",
  "technicalDetails": "The vulnerability exists within the Security & Malware scan by CleanTalk plugin <= 2.184, specifically in how input parameters are handled and processed within database query operations. The root cause is categorized as improper neutralization of special elements used in an SQL command, commonly known as SQL Injection (SQLi).\nThe vulnerable component fails to adequately parameterize or sanitize inputs passed via HTTP requests before they are concatenated directly into SQL statements. Because the application trusts incoming data from unauthenticated users, an attacker can supply malicious SQL payloads designed to alter the logical structure of the intended query.\nThe attack flow begins when an unauthenticated remote threat actor sends a crafted HTTP request containing malicious SQL syntax targeting the vulnerable parameter handled by the Security & Malware scan by CleanTalk plugin. The network exposure is high, as the vulnerable endpoint is accessible externally over HTTP/HTTPS protocols without authentication or privilege requirements.\nUpon receiving the payload, the vulnerable component processes the input and concatenates it directly into the database query string. The database management system executes the resulting malicious query, interpreting the attacker-supplied strings as executable SQL commands rather than inert data literal values.\nThe payload behavior allows the attacker to perform error-based, boolean-based, or time-based blind SQL injections, or union-based data retrieval. Post-exploitation impact includes the potential extraction of the entire WordPress database, including password hashes, session tokens, and administrator credentials. In environments with misconfigured database permissions, this vulnerability could theoretically be leveraged to execute operating system commands or interact with the underlying host file system."
}
CVE-2026-66593: CleanTalk SQL Injection Vulnerability (CRITICAL Severity, CVSS: 9.3) - Sceawere