Impact
The vulnerability is an unauthenticated SQL injection that allows an attacker to supply arbitrary SQL queries which are executed by the WordPress database through the vulnerable plugin. This vulnerability is classified as CWE‑89.
Affected Systems
The affected product is CleanTalk Inc.'s Security & Malware scan by CleanTalk plugin for WordPress. Versions 2.184 and earlier are vulnerable; any installation using these versions remains at risk.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity. The EPSS is not available, but based on the description it is inferred that the lack of authentication requirement permits an attacker to target any visitor who can send requests to the plugin’s exposed endpoints. The vulnerability is not listed in the CISA KEV catalog; therefore, the primary risk stems from its high severity and unauthenticated nature.
OpenCVE Enrichment