Description
WordPress Plugin Security & Malware scan by CleanTalk is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently interact with all its AJAX actions, which could lead to multiple vulnerabilities - from arbitrary file deletion/download to PHP function injection. WordPress Plugin Security & Malware scan by CleanTalk version 2.50 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.51 or latest
References
Related Vulnerabilities
Drupal Core 8.4.x Remote Code Execution (8.4.0 - 8.4.7)
WordPress Plugin WPtouch 'wptouch_redirect' Parameter URI Redirection (1.9.32)
Joomla! Core Security Bypass (1.5.0 - 3.8.12)
WordPress Plugin Import and export users and customers Cross-Site Scripting (1.12)
Jenkins Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2023-35141)