PT-2024-8882 · Cleantalk · Cleantalk
Michael Mazzolini
+1
·
Published
2024-10-23
·
Updated
2025-07-12
·
CVE-2024-10542
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
CleanTalk versions up to and including 6.43.2
Description:
The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is susceptible to unauthorized Arbitrary Plugin Installation due to an authorization bypass. This bypass is achieved through reverse DNS spoofing within the
checkWithoutToken() function. Successful exploitation allows unauthenticated attackers to install and activate arbitrary plugins, potentially leading to remote code execution if another vulnerable plugin is already installed and active.Recommendations:
Update CleanTalk to version 6.43.3.
Fix
RCE
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cleantalk