plugin

Security Malware Firewall Vulnerabilities

14 known security issues reported for the Security Malware Firewall WordPress plugin. Most recent disclosed Aug 19, 2026.

1 critical 4 high 1 medium

Running Security Malware Firewall on your site? Check whether your installed version is affected.

Scan your site free

Security Plugin, Firewall & Malware Scanner with Auto Removal <= 2.184 - Unauthenticated SQL Injection

high

The Security Plugin, Firewall & Malware Scanner with Auto Removal plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.184. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for...

CVSS:
7.5
Affected:
up to 2.184
Fixed in:
2.185
Disclosed:
Aug 19, 2026

CVE-2026-66593 on NVD →

Login Security, FireWall, Malware removal by CleanTalk [security-malware-firewall] < 2.169

unknown

[en] The Login Security, FireWall, Malware removal by CleanTalk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the page URL in all versions up to, and including, 2.168 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitr...

Affected:
up to 2.169
Fixed in:
2.169
Disclosed:
Dec 9, 2025

CVE-2025-13604 on NVD →

Login Security, FireWall, Malware removal by CleanTalk <= 2.168 - Unauthenticated Stored Cross-Site Scripting via Page URL

high

The Login Security, FireWall, Malware removal by CleanTalk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the page URL in all versions up to, and including, 2.168 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary w...

CVSS:
7.2
Affected:
up to 2.168
Fixed in:
2.169
Disclosed:
Dec 8, 2025

CVE-2025-13604 on NVD →

Login Security, FireWall, Malware removal by CleanTalk [security-malware-firewall] < 2.150

unknown

[en] The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to arbitrary file uploads due to the plugin uploading and extracting .zip archives when scanning them for malware through the checkUploadedArchive() function in all versions up to, and including, 2.149. This makes it possible for unauthen...

Affected:
up to 2.150
Fixed in:
2.150
Disclosed:
Feb 12, 2025

CVE-2024-13365 on NVD →

Security & Malware scan by CleanTalk <= 2.149 - Unauthenticated Arbitrary File Upload

critical

The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to arbitrary file uploads due to the plugin uploading and extracting .zip archives when scanning them for malware through the checkUploadedArchive() function in all versions up to, and including, 2.149. This makes it possible for unauthenticat...

CVSS:
9.8
Affected:
up to 2.149
Fixed in:
2.150
Disclosed:
Feb 11, 2025

CVE-2024-13365 on NVD →

Login Security, FireWall, Malware removal by CleanTalk [security-malware-firewall] < 2.145.1

unknown

[en] The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to unauthorized SQL Injection due to an authorization bypass via reverse DNS spoofing on the checkWithoutToken function in all versions up to, and including, 2.145, as well as insufficient input sanitization and validation. This makes it p...

Affected:
up to 2.145.1
Fixed in:
2.145.1
Disclosed:
Nov 26, 2024

CVE-2024-10570 on NVD →

Security & Malware scan by CleanTalk <= 2.145 - Authorization Bypass via Reverse DNS Spoofing to Unauthenticated SQL Injection

high

The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to unauthorized SQL Injection due to an authorization bypass via reverse DNS spoofing on the checkWithoutToken function in all versions up to, and including, 2.145, as well as insufficient input sanitization and validation. This makes it possib...

CVSS:
7.5
Affected:
up to 2.145
Fixed in:
2.145.1
Disclosed:
Nov 25, 2024

CVE-2024-10570 on NVD →

Login Security, FireWall, Malware removal by CleanTalk [security-malware-firewall] < 2.121

unknown

[en] The Security & Malware scan by CleanTalk WordPress plugin before 2.121 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. This may be used to bypass bruteforce protection.

Affected:
up to 2.121
Fixed in:
2.121
Disclosed:
Nov 27, 2023

CVE-2023-5239 on NVD →

Security & Malware scan by CleanTalk <= 2.120 - IP Spoofing to Protection Mechanism Bypass

medium

The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.120. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply the X-Forwarded-For...

CVSS:
5.3
Affected:
up to 2.120
Fixed in:
2.121
Disclosed:
Nov 6, 2023

CVE-2023-5239 on NVD →

Login Security, FireWall, Malware removal by CleanTalk [security-malware-firewall] < 2.51

unknown

[en] The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to unauthorized user interaction in versions up to, and including, 2.50. This is due to missing capability checks on several AJAX actions and nonce disclosure in the source page of the administrative dashboard. This makes it possible for a...

Affected:
up to 2.51
Fixed in:
2.51
Disclosed:
Oct 20, 2023

CVE-2020-36698 on NVD →

Login Security, FireWall, Malware removal by CleanTalk [security-malware-firewall] < 2.80.1

unknown

SQL Injection (SQLi) vulnerability discovered in WordPress Security & Malware scan by CleanTalk plugin (versions <= 2.80).

Affected:
up to 2.80.1
Fixed in:
2.80.1
Disclosed:
Feb 18, 2022

Security & Malware scan by CleanTalk <= 2.50 - Missing Authorization

high

The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to unauthorized user interaction in versions up to, and including, 2.50. This is due to missing capability checks on several AJAX actions and nonce disclosure in the source page of the administrative dashboard. This makes it possible for authen...

CVSS:
8.8
Affected:
up to 2.50
Fixed in:
2.51
Disclosed:
Jul 6, 2020

CVE-2020-36698 on NVD →

Login Security, FireWall, Malware removal by CleanTalk [security-malware-firewall] < 2.51

unknown

The WordPress Security Scanner plugin for WordPress is vulnerable to unauthorized user interaction in versions up to, and including, 2.50. This is due to missing capability checks on several AJAX actions and nonce disclosure in the source page of the administrative dashboard. This makes it possible for authenticated at...

Affected:
up to 2.51
Fixed in:
2.51

Login Security, FireWall, Malware removal by CleanTalk [security-malware-firewall] < 2.51

unknown

Security nonce leak, allowing any authenticated users (such as subscribers) to make unauthorised AJAX call which could lead to arbitrary file deletion/download and function call. Note (WPScanTeam): We do not consider the issue fully remediated, as the AJAX calls rely on CSRF check for authorisation, instead of prop...

Affected:
up to 2.51
Fixed in:
2.51

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database