CVE-2023-5239

The Security & Malware scan by CleanTalk WordPress plugin before 2.121 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. This may be used to bypass bruteforce protection.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:cleantalk:security_\&_malware_scan:*:*:*:*:*:wordpress:*:*

History

01 Dec 2023, 19:22

Type Values Removed Values Added
CPE cpe:2.3:a:cleantalk:security_\&_malware_scan:*:*:*:*:*:wordpress:*:*
References () https://wpscan.com/vulnerability/1d748f91-773b-49d6-8f68-a27d397713c3 - () https://wpscan.com/vulnerability/1d748f91-773b-49d6-8f68-a27d397713c3 - Exploit, Third Party Advisory
First Time Cleantalk
Cleantalk security \& Malware Scan
CWE NVD-CWE-noinfo
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

27 Nov 2023, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-11-27 17:15

Updated : 2023-12-01 19:22


NVD link : CVE-2023-5239

Mitre link : CVE-2023-5239


JSON object : View

Products Affected

cleantalk

  • security_\&_malware_scan