Description
WordPress Plugin Security & Malware scan by CleanTalk is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently interact with all its AJAX actions, which could lead to multiple vulnerabilities - from arbitrary file deletion/download to PHP function injection. WordPress Plugin Security & Malware scan by CleanTalk version 2.50 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.51 or latest
References
Related Vulnerabilities
WordPress Plugin SAML SP Single Sign On-SSO login Unspecified Vulnerability (4.8.70)
WordPress Plugin Social Media Flying Icons-Floating Social Media Icon Cross-Site Scripting (2.1)
WordPress Plugin Light Messages Cross-Site Request Forgery (1.0)
Jboss EAP Deserialization of Untrusted Data Vulnerability (CVE-2021-4104)