Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3
Critical2
High1
Medium0
Reset
Showing 1-3 of 3 records
Threat Entry Updated 2026-04-15

CVE-2026-1490 - Cleantalk Spam Protect Plugin

The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an authorization bypass via reverse DNS (PTR record) spoofing on the 'checkWithoutToken' function in all versions up to, and including, 6.71. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated. Note: This is only exploitable on sites with an invalid API key.

PLUGIN Cleantalk Spam Protect

CVE-2026-1490

CRITICAL CVSS 9.8 2026-02-15
Threat Entry Updated 2025-07-12

CVE-2024-10781 - Cleantalk Spam Protect Plugin

The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an missing empty value check on the 'api_key' value in the 'perform' function in all versions up to, and including, 6.44. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated.

PLUGIN Cleantalk Spam Protect

CVE-2024-10781

HIGH CVSS 8.1 2024-11-26
Threat Entry Updated 2025-07-12

CVE-2024-10542 - Cleantalk Spam Protect Plugin

The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an authorization bypass via reverse DNS spoofing on the checkWithoutToken function in all versions up to, and including, 6.43.2. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated.

PLUGIN Cleantalk Spam Protect

CVE-2024-10542

CRITICAL CVSS 9.8 2024-11-26
Scroll to top