Description
WordPress Plugin Security & Malware scan by CleanTalk is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently interact with all its AJAX actions, which could lead to multiple vulnerabilities - from arbitrary file deletion/download to PHP function injection. WordPress Plugin Security & Malware scan by CleanTalk version 2.50 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.51 or latest
References
Related Vulnerabilities
WordPress Plugin Magic Fields 2 Cross-Site Scripting (2.3.2.4)
WordPress Plugin Alpine PhotoTile for Instagram Cross-Site Scripting (1.2.7.7)
Ruby Cryptographic Issues Vulnerability (CVE-2013-4363)
WordPress Plugin Media Library Categories 'termid' Parameter SQL Injection (1.0.6)
OpenSSL Improper Authentication Vulnerability (CVE-2009-0591)