PT-2024-8882 · Cleantalk · Cleantalk

Michael Mazzolini

+1

·

Published

2024-10-23

·

Updated

2025-07-12

·

CVE-2024-10542

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: CleanTalk versions up to and including 6.43.2
Description: The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is susceptible to unauthorized Arbitrary Plugin Installation due to an authorization bypass. This bypass is achieved through reverse DNS spoofing within the checkWithoutToken() function. Successful exploitation allows unauthenticated attackers to install and activate arbitrary plugins, potentially leading to remote code execution if another vulnerable plugin is already installed and active.
Recommendations: Update CleanTalk to version 6.43.3.

Fix

RCE

Missing Authorization

Weakness Enumeration

Related Identifiers

BDU:2024-10549
CVE-2024-10542

Affected Products

Cleantalk