Plugins Garbage Collector (Database Cleanup)
Plugins Garbage Collector (Database Cleanup) has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it is fixed as of August 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for Plugins Garbage Collector (Database Cleanup) has a vendor fix available, so running the current release closes it.
All of these findings were reported by Ananda Dhakal. Plugins Garbage Collector (Database Cleanup) is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2026-66686Plugins Garbage Collector (Database Cleanup) <= 0.14 - Cross-Site Request Forgery
Read the full analysisVulnerability Records

Plugins Garbage Collector (Database Cleanup)
Author
Vladimir Garagulya
Database Cleanup plugin scans the database and shows the tables beyond of core WordPress installation. Some WordPress plugins create and use its own database tables. Those tables are left in your database after plugin deactivation and deletion often. With the help of this plugin you can check your database and discover if it is clean or not. Extra columns added to the core WordPress tables could be shown also. To read more about ‘Plugins Garbage Collector’ visit this link at shinephp.com Additional Documentation You can find more information about “Plugins Garbage Collector” plugin at this page http://www.shinephp.com/plugins-garbage-collector-wordpress-plugin/ I am ready to answer on your questions about this plugin usage. Use plugin page comments or site contact form for that please.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C