PT-2025-6458 · Cleantalk · Security & Malware Scan By Cleantalk

Lucio Sá

·

Published

2025-02-12

·

Updated

2026-04-08

·

CVE-2024-13365

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Security & Malware scan by CleanTalk plugin for WordPress versions up to, and including, 2.149
Description The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to arbitrary file uploads due to the plugin uploading and extracting .zip archives when scanning them for malware through the checkUploadedArchive() function. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server, which may make remote code execution possible. Approximately 30,000 WordPress sites are potentially affected.
Recommendations For versions up to, and including, 2.149, consider disabling the checkUploadedArchive() function as a temporary workaround until a patch is available. Restrict access to the plugin's archive upload feature to minimize the risk of exploitation. Avoid using the plugin for malware scanning until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-13365

Affected Products

Security & Malware Scan By Cleantalk