Spam protection, Anti-Spam, FireWall by CleanTalk <= 6.43.2 - Authorization Bypass via Reverse DNS Spoofing to Unauthenticated Arbitrary Plugin Installation
53Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 9.8epss 15%
from disclosure to weapon0 days
Published on NVDNov 26
1st PoCNov 26
exploitation probability
15%top 4% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an authorization bypass via reverse DNS spoofing on the checkWithoutToken function in all versions up to, and including, 6.43.2. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
cleantalk · Spam protection, Honeypot, Anti-Spam by CleanTalkpublic PoCs found — 1
githubgithub.com/ubaydev/CVE-2024-10542★ 3⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://plugins.trac.wordpress.org/browser/cleantalk-spam-protect/tags/6.43.2/lib/Cleantalk/ApbctWP/RemoteCalls.php#L41https://plugins.trac.wordpress.org/changeset/3179819/cleantalk-spam-protect#file631https://www.wordfence.com/threat-intel/vulnerabilities/id/d7eb5fad-bb62-4f0b-ad52-b16c3e442b62?source=cve