CVE-2024-10781

The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an missing empty value check on the 'api_key' value in the 'perform' function in all versions up to, and including, 6.44. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cleantalk:spam_protection\,_antispam\,_firewall:*:*:*:*:*:wordpress:*:*

History

12 Jul 2025, 00:24

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CPE cpe:2.3:a:cleantalk:spam_protection\,_antispam\,_firewall:*:*:*:*:*:wordpress:*:*
References () https://plugins.trac.wordpress.org/changeset/3188546/cleantalk-spam-protect#file653 - () https://plugins.trac.wordpress.org/changeset/3188546/cleantalk-spam-protect#file653 - Patch
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/79ae062c-b084-4045-9407-2d94919993af?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/79ae062c-b084-4045-9407-2d94919993af?source=cve - Third Party Advisory
References () https://plugins.trac.wordpress.org/browser/cleantalk-spam-protect/tags/6.44/lib/Cleantalk/ApbctWP/RemoteCalls.php#L95 - () https://plugins.trac.wordpress.org/browser/cleantalk-spam-protect/tags/6.44/lib/Cleantalk/ApbctWP/RemoteCalls.php#L95 - Product
References () https://plugins.trac.wordpress.org/browser/cleantalk-spam-protect/tags/6.44/lib/Cleantalk/ApbctWP/RemoteCalls.php#L96 - () https://plugins.trac.wordpress.org/browser/cleantalk-spam-protect/tags/6.44/lib/Cleantalk/ApbctWP/RemoteCalls.php#L96 - Product
First Time Cleantalk
Cleantalk spam Protection\, Antispam\, Firewall

26 Nov 2024, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-26 06:15

Updated : 2025-07-12 00:24


NVD link : CVE-2024-10781

Mitre link : CVE-2024-10781


JSON object : View

Products Affected

cleantalk

  • spam_protection\,_antispam\,_firewall
CWE

No CWE.