{"error":0,"message":null,"data":{"name":"Spam protection, Honeypot, Anti-Spam by CleanTalk","plugin":"cleantalk-spam-protect","link":"https:\/\/wordpress.org\/plugins\/cleantalk-spam-protect\/","latest":"1789623900","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"a71bd30e7e2760267d30b8664a4fc02a806e823744bb977655d04af90e67dd5b","name":"Spam protection, Honeypot, Anti-Spam by CleanTalk [cleantalk-spam-protect] < 5.153.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.153.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-24295","name":"CVE-2021-24295","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-24295","description":"[en] It was possible to exploit an Unauthenticated Time-Based Blind SQL Injection vulnerability in the Spam protection, AntiSpam, FireWall by CleanTalk WordPress Plugin before 5.153.4. The update_log function in lib\/Cleantalk\/ApbctWP\/Firewall\/SFW.php included a vulnerable query that could be injected via the User-Agent Header by manipulating the cookies set by the Spam protection, AntiSpam, FireWall by CleanTalk WordPress plugin before 5.153.4, sending an initial request to obtain a ct_sfw_pass_key cookie and then manually setting a separate ct_sfw_passed cookie and disallowing it from being reset.","date":"2021-05-17"},{"id":"809ecfc35bc1c95c144ec1f18724cd3351c38796","name":"WordPress Spam protection, AntiSpam, FireWall by CleanTalk plugin <= 5.153.3 - Unauthenticated Time-Based Blind SQL Injection (SQLi) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/cleantalk-spam-protect\/vulnerability\/wordpress-spam-protection-antispam-firewall-by-cleantalk-plugin-5-153-3-unauthenticated-time-based-blind-sql-injection-sqli-vulnerability","description":"Unauthenticated Time-Based Blind SQL Injection (SQLi) vulnerability discovered by WordFence in WordPress Spam protection, AntiSpam, FireWall by CleanTalk plugin (versions <= 5.153.3).","date":"2021-05-03"},{"id":"152171fc-888c-4275-a118-5a1e664ef28b","name":"Spam protection, AntiSpam, FireWall by CleanTalk &lt; 5.153.4 - Unauthenticated Blind SQL Injection","link":"https:\/\/wpscan.com\/vulnerability\/152171fc-888c-4275-a118-5a1e664ef28b","description":"It was possible to exploit an Unauthenticated Time-Based Blind SQL Injection vulnerability in the Spam protection, AntiSpam, FireWall by CleanTalk WordPress Plugin before 5.153.4. The update_log function in lib\/Cleantalk\/ApbctWP\/Firewall\/SFW.php included a vulnerable query that could be injected via the User-Agent Header by manipulating the cookies set by the plugin, sending an initial request to obtain a ct_sfw_pass_key cookie and then manually setting a separate ct_sfw_passed cookie and disallowing it from being reset.","date":null},{"id":"19819f075d19903f7f83d104f01e1e4ad0095f73","name":"Spam protection, AntiSpam, FireWall by CleanTalk <= 5.153.3 - Unauthenticated Blind SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/cleantalk-spam-protect\/spam-protection-antispam-firewall-by-cleantalk-51533-unauthenticated-blind-sql-injection","description":"It was possible to exploit an Unauthenticated Time-Based Blind SQL Injection vulnerability in the Spam protection, AntiSpam, FireWall by CleanTalk WordPress Plugin before 5.153.4. The update_log function in lib\/Cleantalk\/ApbctWP\/Firewall\/SFW.php included a vulnerable query that could be injected via the User-Agent Header by manipulating the cookies set by the Spam protection, AntiSpam, FireWall by CleanTalk WordPress plugin before 5.153.4, sending an initial request to obtain a ct_sfw_pass_key cookie and then manually setting a separate ct_sfw_passed cookie and disallowing it from being reset.","date":"2021-03-05"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"7.5","severity":"h","exploitable":"3.9","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"7.5","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"3.9","impact":"3.6"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}]}},{"uuid":"197aa9d78d78c5b39e34b312c5c88e0683aa192379e6e6fb742a2b4ee0543b8f","name":"Spam protection, Honeypot, Anti-Spam by CleanTalk [cleantalk-spam-protect] < 5.149","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.149","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-24131","name":"CVE-2021-24131","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-24131","description":"[en] Unvalidated input in the Anti-Spam by CleanTalk WordPress plugin, versions before 5.149, lead to multiple authenticated SQL injection vulnerabilities, however, it requires high privilege user (admin+).","date":"2021-03-18"},{"id":"1bc28021-28c0-43fa-b89e-6b93c345e5d8","name":"Anti-Spam by CleanTalk &lt; 5.149 - Multiple Authenticated SQL Injections","link":"https:\/\/wpscan.com\/vulnerability\/1bc28021-28c0-43fa-b89e-6b93c345e5d8","description":"Multiple authenticated SQL injections in the Anti-Spam by CleanTalk plugin 5.148 exist, however, it requires high privilege user (admin+).","date":null},{"id":"1a396f6242c792b490fb81d06017e8844ecb2611","name":"Anti-Spam by CleanTalk < 5.149 - Authenticated SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/cleantalk-spam-protect\/anti-spam-by-cleantalk-5149-authenticated-sql-injection","description":"Unvalidated input in the Anti-Spam by CleanTalk WordPress plugin, versions before 5.149, lead to multiple authenticated SQL injection vulnerabilities, however, it requires high privilege user (admin+).","date":"2020-11-20"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"h","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"7.2","severity":"h","exploitable":"1.2","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"7.2","severity":"high","av":"network","ac":"low","pr":"high","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"1.2","impact":"5.9"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}]}},{"uuid":"290c73a16f69cbb2c4c1b5c0c7d82c5530deca1bc9639401d02e18a779761b84","name":"Spam protection, Honeypot, Anti-Spam by CleanTalk [cleantalk-spam-protect] < 5.127.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.127.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2019-17515","name":"CVE-2019-17515","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2019-17515","description":"[en] The CleanTalk cleantalk-spam-protect plugin before 5.127.4 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via the from or till parameter. The component is: inc\/cleantalk-users.php and inc\/cleantalk-comments.php. The attack vector is: When the Administrator is logged in, a reflected XSS may execute upon a click on a malicious URL.","date":"2019-11-13"},{"id":"7b6731e7654978ba9cd77025ee19cdfa6d0538b0","name":"WordPress Spam protection, AntiSpam, FireWall by CleanTalk plugin <=5.127.3 - Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/cleantalk-spam-protect\/vulnerability\/wordpress-spam-protection-antispam-firewall-by-cleantalk-plugin-5-127-3-cross-site-scripting-xss-vulnerability","description":"Cross-Site Scripting (XSS) vulnerability found in WordPress Spam protection, AntiSpam, FireWall by CleanTalk plugin (versions <=5.127.3).","date":"2019-11-14"},{"id":"204e9fcd-6fd4-462d-a422-5e420ebca3a0","name":"Anti-Spam by CleanTalk &lt; 5.127.4 - Cross-Site Scripting Issue","link":"https:\/\/wpscan.com\/vulnerability\/204e9fcd-6fd4-462d-a422-5e420ebca3a0","description":"The Spam protection, AntiSpam, FireWall by CleanTalk WordPress plugin was affected by a Cross-Site Scripting Issue security vulnerability.","date":null},{"id":"674d544b634704beb8a8670157c983693b078da0","name":"Spam protection, AntiSpam, FireWall by CleanTalk <= 5.127.3 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/cleantalk-spam-protect\/spam-protection-antispam-firewall-by-cleantalk-51273-reflected-cross-site-scripting","description":"The CleanTalk cleantalk-spam-protect plugin before 5.127.4 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via the from or till parameter. The component is: inc\/cleantalk-users.php and inc\/cleantalk-comments.php. The attack vector is: When the Administrator is logged in, a reflected XSS may execute upon a click on a malicious URL.","date":"2019-11-12"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"4c4ce56a030cfca3cb39c0b4866f1c65b8b3b58279d5a0c96e80d0c25ddb5ac4","name":"Spam protection, Honeypot, Anti-Spam by CleanTalk [cleantalk-spam-protect] < 5.174.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.174.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-28222","name":"CVE-2022-28222","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-28222","description":"[en] The CleanTalk AntiSpam plugin <= 5.173 for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) via the $_REQUEST['page'] parameter in`\/lib\/Cleantalk\/ApbctWP\/FindSpam\/ListTable\/Users.php`","date":"2022-04-19"},{"id":"2284e81ca1c1df0dc1a7f6460fa1047b7bfcc551","name":"WordPress Spam protection, AntiSpam, FireWall by CleanTalk plugin <= 5.174 - Reflected Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/cleantalk-spam-protect\/vulnerability\/wordpress-spam-protection-antispam-firewall-by-cleantalk-plugin-5-174-reflected-cross-site-scripting-xss-vulnerability-1","description":"Reflected Cross-Site Scripting (XSS) vulnerability discovered by Ramuel Gall (Wordfence) in WordPress Spam protection, AntiSpam, FireWall by CleanTalk plugin (versions <= 5.174).","date":"2022-03-30"},{"id":"4f68d896-1cb7-430c-b187-918c9f92005d","name":"Spam protection, AntiSpam, FireWall by CleanTalk &lt; 5.174.1 - Reflected Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/4f68d896-1cb7-430c-b187-918c9f92005d","description":"The plugin does not not sanitise and escape the page parameter brief outputting it back in attributes in the \/wp-admin\/edit-comments.php?page=ct_check_spam and Users list dashboard, leading to Reflected Cross-Site Scripting issues","date":null},{"id":"226d58ce8b96b94aa9397c9282d4ba2ac246d105","name":"Spam protection, AntiSpam, FireWall by CleanTalk <= 5.173 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/cleantalk-spam-protect\/spam-protection-antispam-firewall-by-cleantalk-5173-reflected-cross-site-scripting","description":"The CleanTalk AntiSpam plugin <= 5.173 for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) via the $_REQUEST['page'] parameter in the  \/lib\/Cleantalk\/ApbctWP\/FindSpam\/ListTable\/Users.php file.","date":"2022-03-30"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"08f090dbd2e67a69ed94c21b24194ace86e46bf4f95eb5fefef7117cefe47104","name":"Spam protection, Honeypot, Anti-Spam by CleanTalk [cleantalk-spam-protect] < 5.174.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.174.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-28221","name":"CVE-2022-28221","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-28221","description":"[en] The CleanTalk AntiSpam plugin <= 5.173 for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) via the $_REQUEST['page'] parameter in`\/lib\/Cleantalk\/ApbctWP\/FindSpam\/ListTable\/Comments.php`","date":"2022-04-19"},{"id":"db99da7167b1c5ad3c3474be486c83e72a787717","name":"WordPress Spam protection, AntiSpam, FireWall by CleanTalk plugin <= 5.174 - Reflected Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/cleantalk-spam-protect\/vulnerability\/wordpress-spam-protection-antispam-firewall-by-cleantalk-plugin-5-174-reflected-cross-site-scripting-xss-vulnerability","description":"Reflected Cross-Site Scripting (XSS) vulnerability discovered by Ramuel Gall (Wordfence) in WordPress Spam protection, AntiSpam, FireWall by CleanTalk plugin (versions <= 5.174).","date":"2022-03-30"},{"id":"32216bef113d863a532946d1c3263897b46c1a15","name":"Spam protection, AntiSpam, FireWall by CleanTalk <= 5.173 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/cleantalk-spam-protect\/spam-protection-antispam-firewall-by-cleantalk-5173-reflected-cross-site-scripting-2","description":"The CleanTalk AntiSpam plugin <= 5.173 for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) via the $_REQUEST['page'] parameter found in the \/lib\/Cleantalk\/ApbctWP\/FindSpam\/ListTable\/Comments.php file.","date":"2022-03-30"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"4468f0e427843ee194f5af8eedca6788ecf63d62479dd58ef60369d59a6138fa","name":"Spam protection, Honeypot, Anti-Spam by CleanTalk [cleantalk-spam-protect] < 5.149","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.149","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"e98e54f7684b9d0278bffcf60f53299cf3a4f176","name":"WordPress Anti-Spam by CleanTalk plugin <= 5.148 - Multiple Authenticated SQL Injection (SQLi) vulnerabilities","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/cleantalk-spam-protect\/vulnerability\/wordpress-anti-spam-by-cleantalk-plugin-5-148-multiple-authenticated-sql-injection-sqli-vulnerabilities","description":"Multiple Authenticated SQL Injection (SQLi) vulnerabilities found by Nguyen Anh Tien in WordPress Anti-Spam by CleanTalk plugin (versions <= 5.148).","date":"2020-11-20"}],"impact":[]},{"uuid":"bd3e486f024b359615045dc5ae30ec4902fb81b1081ccf75607f32c484424ebe","name":"Spam protection, Honeypot, Anti-Spam by CleanTalk [cleantalk-spam-protect] < 5.22","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.22","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"b0171cd0006b761da43ebc5cfdb81aff7260358e","name":"WordPress Spam Protection Plugin <= 5.21 - Cross Site Scripting","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/cleantalk-spam-protect\/vulnerability\/wordpress-spam-protection-plugin-5-21-cross-site-scripting","description":"Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.\nUpdate the plugin.","date":"2015-08-25"}],"impact":[]},{"uuid":"8937c6ff796266df191b9ab7c19e0566753c17507b75df2f4c3ef8a76afff3d9","name":"Spam protection, Honeypot, Anti-Spam by CleanTalk [cleantalk-spam-protect] < 5.185.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.185.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-3302","name":"CVE-2022-3302","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-3302","description":"[en] The Spam protection, AntiSpam, FireWall by CleanTalk WordPress plugin before 5.185.1 does not validate ids before using them in a SQL statement, which could lead to SQL injection exploitable by high privilege users such as admin","date":"2022-10-25"},{"id":"8390e9b65b5bce5629215149c1984371be640e83","name":"WordPress AntiSpam by CleanTalk plugin <= 5.185 - Authenticated SQL Injection (SQLi) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/cleantalk-spam-protect\/vulnerability\/wordpress-anti-spam-by-cleantalk-plugin-5-185-authenticated-sql-injection-sqli-vulnerability","description":"Authenticated SQL Injection (SQLi) vulnerability discovered by Nguyen Duy Quoc Khanh in WordPress Anti-Spam by CleanTalk plugin (versions <= 5.185).\nUpdate the WordPress Spam protection, AntiSpam, FireWall by CleanTalk plugin to the latest available version (at least 5.185.1).","date":"2022-10-03"},{"id":"7fd16d0ee42b2cac5cdda35225a754808d55bc4c","name":"AntiSpam by CleanTalk <= 5.185 - Authenticated (Administrator+) SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/cleantalk-spam-protect\/antispam-by-cleantalk-5185-authenticated-administrator-sql-injection","description":"The AntiSpam plugin for WordPress is vulnerable to SQL Injection via the \u2018ids\u2019 parameter in versions up to, and including, 5.185 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level privileges or higher, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2022-10-03"},{"id":"1b5a018d-f2d4-4373-be1e-5162cc5c928b","name":"Anti-Spam by CleanTalk &lt; 5.185.1 - Admin+ SQLi","link":"https:\/\/wpscan.com\/vulnerability\/1b5a018d-f2d4-4373-be1e-5162cc5c928b","description":"The plugin does not validate ids before using them in a SQL statement, which could lead to SQL injection exploitable by high privilege users such as admin","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"h","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"7.2","severity":"h","exploitable":"1.2","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"7.2","severity":"high","av":"network","ac":"low","pr":"high","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"1.2","impact":"5.9"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"5d85113aefeca40ae0653c6f9c742d755c19d4de5695473558b24f625f3289fd","name":"Spam protection, Honeypot, Anti-Spam by CleanTalk [cleantalk-spam-protect] < 5.22","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.22","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"982c7cef-eb17-49c4-9a92-87a5d0aca29b","name":"Anti-Spam by CleanTalk &lt; 5.22 - Unauthenticated Reflected Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/982c7cef-eb17-49c4-9a92-87a5d0aca29b","description":"The Spam protection, AntiSpam, FireWall by CleanTalk WordPress plugin was affected by an Unauthenticated Reflected Cross-Site Scripting (XSS) security vulnerability.","date":null}],"impact":[]},{"uuid":"7fc9fa2a1998295cf789995fa85e7bddf552c83d6635879b20381538613e8dd2","name":"Spam protection, Honeypot, Anti-Spam by CleanTalk [cleantalk-spam-protect] < 5.22","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.22","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"f01f8accef07398569b50193551a58fc2ef8f6ae","name":"Spam protection, AntiSpam, FireWall by CleanTalk < 5.22 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/cleantalk-spam-protect\/spam-protection-antispam-firewall-by-cleantalk-522-reflected-cross-site-scripting","description":"The Spam protection, AntiSpam, FireWall by CleanTalk plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions before 5.22 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2015-08-25"}],"impact":[]},{"uuid":"8183decbc37e766fc1e0c2d014d6bb89360b3bd1f84089e1da38150031a176e7","name":"Spam protection, Honeypot, Anti-Spam by CleanTalk [cleantalk-spam-protect] < 6.11","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.11","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-33996","name":"CVE-2023-33996","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-33996","description":"[en] Missing Authorization vulnerability in \u0421leanTalk - Anti-Spam Protection Spam protection, AntiSpam, FireWall by CleanTalk allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spam protection, AntiSpam, FireWall by CleanTalk: from n\/a through 6.10.","date":"2024-12-13"},{"id":"e189ed2a63af502b0398976db22dc0479af4d972","name":"WordPress  Spam protection, AntiSpam, FireWall by CleanTalk Plugin  <= 6.10 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/cleantalk-spam-protect\/vulnerability\/wordpress-spam-protection-antispam-firewall-by-cleantalk-plugin-6-10-broken-access-control-vulnerability","description":"Update the WordPress Spam protection, AntiSpam, FireWall by CleanTalk plugin to the latest available version (at least 6.11).\nRafshanzani Suhada discovered and reported this Broken Access Control vulnerability in WordPress Spam protection, AntiSpam, FireWall by CleanTalk Plugin.  This vulnerability has been fixed in version 6.11.","date":"2023-06-22"},{"id":"ce7f3d30deae29bd093ef82333fd0fc32057afde","name":"Spam protection, AntiSpam, FireWall by CleanTalk <= 6.10 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/cleantalk-spam-protect\/spam-protection-antispam-firewall-by-cleantalk-610-missing-authorization","description":"The Spam protection, AntiSpam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on several functions along with nonce disclosure in versions up to, and including, 6.10. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify\/export\/import templates and trash\/spam\/modify comments among some other actions.","date":"2023-06-22"},{"id":"EUVD-2023-38120","name":"EUVD-2023-38120","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2023-38120","description":"Missing Authorization vulnerability in \u0421leanTalk - Anti-Spam Protection Spam protection, AntiSpam, FireWall by CleanTalk allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spam protection, AntiSpam, FireWall by CleanTalk: from n\/a through 6.10.","date":"2024-12-13"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null},"epss":"0.003"}},{"uuid":"e35f5e22d62931b2b41fa92642b5553cdbd634b8f29c2b700df21c52d71d17d6","name":"Spam protection, Honeypot, Anti-Spam by CleanTalk [cleantalk-spam-protect] < 6.21","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.21","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-51696","name":"CVE-2023-51696","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-51696","description":"[en] Cross-Site Request Forgery (CSRF) vulnerability in \u0421leanTalk - Anti-Spam Protection Spam protection, Anti-Spam, FireWall by CleanTalk.This issue affects Spam protection, Anti-Spam, FireWall by CleanTalk: from n\/a through 6.20.","date":"2024-02-29"},{"id":"6149f3a8779b19532d38ef98ab0c395ae1f16eb7","name":"WordPress  Spam protection, AntiSpam, FireWall by CleanTalk Plugin  <= 6.20 is vulnerable to Cross Site Request Forgery (CSRF)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/cleantalk-spam-protect\/vulnerability\/wordpress-spam-protection-antispam-firewall-by-cleantalk-anti-spam-plugin-6-20-cross-site-request-forgery-csrf-vulnerability","description":"Update the WordPress Spam protection, AntiSpam, FireWall by CleanTalk plugin to the latest available version (at least 6.21).\nElliot discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Spam protection, AntiSpam, FireWall by CleanTalk Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has been fixed in version 6.21.\nHave additional information or questions about this entry? Get in touch.","date":"2024-12-27"},{"id":"d8e0788b956a2fad72c3cc8cea373a71a9af1b51","name":"Spam protection, AntiSpam, FireWall by CleanTalk <= 6.20 - Cross-Site Request Forgery via apbct_settings__update_account_email","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/cleantalk-spam-protect\/spam-protection-antispam-firewall-by-cleantalk-620-cross-site-request-forgery-via-apbct-settings-update-account-email","description":"The Spam protection, AntiSpam, FireWall by CleanTalk plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.20. This is due to missing or incorrect nonce validation on the apbct_settings__update_account_email  function. This makes it possible for unauthenticated attackers to update the account email via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2023-12-27"},{"id":"9ba44969-d6d0-4933-80fc-f954acf7ed4a","name":"Spam protection, AntiSpam, FireWall by CleanTalk &lt; 6.21 - Email Update via CSRF","link":"https:\/\/wpscan.com\/vulnerability\/9ba44969-d6d0-4933-80fc-f954acf7ed4a","description":"The plugin does not have CSRF check in its apbct_settings__update_account_email function, which could allow attackers to make logged in admins update email address via a CSRF attack","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"9e8d5a41dbbda7987fa7262b9070c7f9d953eaf6d834f7eade2e1151e73aaedf","name":"Spam protection, Honeypot, Anti-Spam by CleanTalk [cleantalk-spam-protect] < 6.21","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.21","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-51535","name":"CVE-2023-51535","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-51535","description":"[en] Cross-Site Request Forgery (CSRF) vulnerability in \u0421leanTalk - Anti-Spam Protection Spam protection, Anti-Spam, FireWall by CleanTalk.This issue affects Spam protection, Anti-Spam, FireWall by CleanTalk: from n\/a through 6.20.","date":"2024-01-05"},{"id":"f66cb5d5eeaa77e3b10a9b913b525231911f60c6","name":"WordPress  Spam protection, AntiSpam, FireWall by CleanTalk Plugin  <= 6.20 is vulnerable to Cross Site Request Forgery (CSRF)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/cleantalk-spam-protect\/vulnerability\/wordpress-spam-protection-anti-spam-firewall-by-cleantalk-plugin-6-20-cross-site-request-forgery-csrf-vulnerability","description":"Update the WordPress Spam protection, AntiSpam, FireWall by CleanTalk plugin to the latest available version (at least 6.21).\nBrandon Roldan discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Spam protection, AntiSpam, FireWall by CleanTalk Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has been fixed in version 6.21.\nHave additional information or questions about this entry? Get in touch.","date":"2024-12-27"},{"id":"c47b2aa0441fb2145eeb5c86e5c41e3b63977319","name":"Spam protection, AntiSpam, FireWall by CleanTalk <= 6.20 - Cross-Site Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/cleantalk-spam-protect\/spam-protection-antispam-firewall-by-cleantalk-620-cross-site-request-forgery","description":"The Spam protection, AntiSpam, FireWall by CleanTalk plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.20. This is due to missing or incorrect nonce validation on the apbct_admin__admin_bar__prepare_counters() function. This makes it possible for unauthenticated attackers to prepare counters via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2023-12-27"},{"id":"d770c511-a5b2-4963-a4d1-9525c42cafff","name":"Spam protection, AntiSpam, FireWall by CleanTalk &lt; 6.21 - Counters Reset\/Creation via CSRF","link":"https:\/\/wpscan.com\/vulnerability\/d770c511-a5b2-4963-a4d1-9525c42cafff","description":"The plugin does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks, such as reset\/create counters","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"21bbb652bd33939bc4f36200f35c0a074296744d8a1ca2ad6d2bcde44b14ad04","name":"Spam protection, Honeypot, Anti-Spam by CleanTalk [cleantalk-spam-protect] < 6.44","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.44","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-10542","name":"CVE-2024-10542","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-10542","description":"[en] The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an authorization bypass via reverse DNS spoofing on the checkWithoutToken function in all versions up to, and including, 6.43.2. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated.","date":"2024-11-26"},{"id":"56233a95c1f0be5f5283ee3f4ec650dd9283193a","name":"Spam protection, Anti-Spam, FireWall by CleanTalk <= 6.43.2 - Authorization Bypass via Reverse DNS Spoofing to Unauthenticated Arbitrary Plugin Installation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/cleantalk-spam-protect\/spam-protection-anti-spam-firewall-by-cleantalk-6432-authorization-bypass-via-reverse-dns-spoofing-to-unauthenticated-arbitrary-plugin-installation","description":"The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an authorization bypass via reverse DNS spoofing on the checkWithoutToken function in all versions up to, and including, 6.43.2. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated.","date":"2024-11-25"},{"id":"f116d8428217487fba5e534059b813b1afed3f4f","name":"WordPress Spam protection, AntiSpam, FireWall by CleanTalk Plugin <= 6.43.2 is vulnerable to Broken Authentication","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/cleantalk-spam-protect\/vulnerability\/wordpress-spam-protection-anti-spam-firewall-by-cleantalk-plugin-6-43-2-authorization-bypass-via-reverse-dns-spoofing-vulnerability","description":"<p>WordPress Spam protection, AntiSpam, FireWall by CleanTalk Plugin <= 6.43.2 is vulnerable to Broken Authentication<\/p><p>Software: Spam protection, AntiSpam, FireWall by CleanTalk<\/p><p>Link: https:\/\/wordpress.org\/plugins\/cleantalk-spam-protect\/#developers<\/p><p>Affected Version <= 6.43.2<\/p><p>Fixed in version 6.44 <\/p>","date":"2024-11-25"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"9.8","severity":"c","exploitable":"3.9","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"9.8","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"3.9","impact":"3.6"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"4cb489ea442ec3affcad0265393c170d5586876e037c205e52034d11ab1a1de0","name":"Spam protection, Honeypot, Anti-Spam by CleanTalk [cleantalk-spam-protect] < 6.45","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.45","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-10781","name":"CVE-2024-10781","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-10781","description":"[en] The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an missing empty value check on the 'api_key' value in the 'perform' function in all versions up to, and including, 6.44. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated.","date":"2024-11-26"},{"id":"447c54ca13d4d8b1d04a7cf195c8393a9e1facd2","name":"Spam protection, Anti-Spam, FireWall by CleanTalk <= 6.44 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Arbitrary Plugin Installation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/cleantalk-spam-protect\/spam-protection-anti-spam-firewall-by-cleantalk-644-authorization-bypass-due-to-missing-empty-value-check-to-unauthenticated-arbitrary-plugin-installation","description":"The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an missing empty value check on the 'api_key' value in the 'perform' function in all versions up to, and including, 6.44. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated.","date":"2024-11-25"},{"id":"9b79ad6756799bff1fc8603ee522b8fa6f483de4","name":"WordPress Spam protection, AntiSpam, FireWall by CleanTalk Plugin <= 6.44 is vulnerable to Broken Authentication","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/cleantalk-spam-protect\/vulnerability\/wordpress-spam-protection-anti-spam-firewall-by-cleantalk-plugin-6-44-authorization-bypass-vulnerability","description":"<p>WordPress Spam protection, AntiSpam, FireWall by CleanTalk Plugin <= 6.44 is vulnerable to Broken Authentication<\/p><p>Software: Spam protection, AntiSpam, FireWall by CleanTalk<\/p><p>Link: https:\/\/wordpress.org\/plugins\/cleantalk-spam-protect\/#developers<\/p><p>Affected Version <= 6.44<\/p><p>Fixed in version 6.45 <\/p>","date":"2024-11-25"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"h","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"8.1","severity":"h","exploitable":"3.9","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"8.1","severity":"high","av":"network","ac":"high","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"3.9","impact":"3.6"},"cwe":[{"cwe":"CWE-703","name":"Improper Check or Handling of Exceptional Conditions","description":"The product does not properly anticipate or handle exceptional conditions that rarely occur during normal operation of the product."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"0103440126f633385e8979692342676cf6529701ec6c3f29e2e1931827188ff4","name":"Spam protection, Honeypot, Anti-Spam by CleanTalk [cleantalk-spam-protect] < 6.72","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.72","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-1490","name":"Spam protection, Honeypot, Anti-Spam by CleanTalk <= 6.71 - Authorization Bypass via Reverse DNS (PTR record) Spoofing to Unauthenticated Arbitrary Plugin Installation","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-1490","description":"The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an authorization bypass via reverse DNS (PTR record) spoofing on the 'checkWithoutToken' function in all versions up to, and including, 6.71. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated. Note: This is only exploitable on sites with an invalid API key.","date":"0000-00-00"},{"id":"EUVD-2026-5835","name":"EUVD-2026-5835","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2026-5835","description":"The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an authorization bypass via reverse DNS (PTR record) spoofing on the 'checkWithoutToken' function in all versions up to, and including, 6.71. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated. Note: This is only exploitable on sites with an invalid API key.","date":"2026-02-15"},{"id":"705e97cc8f90eef649e5bb7a9ac28f5219b77a5b","name":"Spam protection, Honeypot, Anti-Spam by CleanTalk <= 6.71 - Authorization Bypass via Reverse DNS (PTR record) Spoofing to Unauthenticated Arbitrary Plugin Installation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/cleantalk-spam-protect\/spam-protection-honeypot-anti-spam-by-cleantalk-671-authorization-bypass-via-reverse-dns-ptr-record-spoofing-to-unauthenticated-arbitrary-plugin-installation","description":"The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an authorization bypass via reverse DNS (PTR record) spoofing on the 'checkWithoutToken' function in all versions up to, and including, 6.71. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated. Note: This is only exploitable on sites with an invalid API key.","date":"2026-02-14"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"9.8","severity":"c","exploitable":"3.9","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"9.8","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"3.9","impact":"5.9"},"cwe":[{"cwe":"CWE-350","name":"Reliance on Reverse DNS Resolution for a Security-Critical Action","description":"The product performs reverse DNS resolution on an IP address to obtain the hostname and make a security decision, but it does not properly ensure that the IP address is truly associated with the hostname."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"495f31d8cf7a995e8f1da7acab0229bd185c95240a96be9c08695bbb26bbb38e","name":"Spam protection, Honeypot, Anti-Spam by CleanTalk [cleantalk-spam-protect] < 6.79","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.79","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-8071","name":"CVE-2026-8071","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-8071","description":"[en] The Anti-Spam by CleanTalk. Spam protection WordPress plugin before 6.79 does not properly sanitize content within a custom shortcode used in its email-encoding feature, allowing unauthenticated attackers to inject arbitrary web scripts into approved comments that will execute when any user (including administrators) views the post.","date":"2026-06-10"},{"id":"42348f1442b95e68b6dfb8648ebbc4ea68bfebe8","name":"WordPress Spam protection, AntiSpam, FireWall by CleanTalk Plugin < 6.79 is vulnerable to a medium priority Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/cleantalk-spam-protect\/vulnerability\/wordpress-spam-protection-honeypot-anti-spam-by-cleantalk-plugin-6-79-unauthenticated-stored-xss-via-comment-shortcode-bypass-vulnerability","description":"<p>WordPress Spam protection, AntiSpam, FireWall by CleanTalk Plugin < 6.79 is vulnerable to a medium priority Cross Site Scripting (XSS)<\/p><p>Software: Spam protection, AntiSpam, FireWall by CleanTalk<\/p><p>Fixed in version 6.79 <\/p><p>Affected Version < 6.79<\/p><p>CVE: CVE-2026-8071<\/p>","date":"2026-06-11"},{"id":"146521a167c85e303288ac28b74b6caafbc16adb","name":"CleanTalk Anti-Spam. Spam Firewall & Bot protection < 6.79 - Unauthenticated Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/cleantalk-spam-protect\/cleantalk-anti-spam-spam-firewall-bot-protection-679-unauthenticated-stored-cross-site-scripting","description":"The CleanTalk Anti-Spam. Spam Firewall & Bot protection plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 6.79 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-06-11"}],"impact":{"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"27878d55799e120ec50cba35b375b6aa40ae33f444cd23a7ab6737024bb65b18","name":"Spam protection, Honeypot, Anti-Spam by CleanTalk [cleantalk-spam-protect] < 6.83","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.83","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-65437","name":"CVE-2026-65437","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-65437","description":"[en] Unauthenticated Cross Site Scripting (XSS) in Spam protection, AntiSpam, FireWall by CleanTalk <= 6.82 versions.","date":"2026-07-27"},{"id":"274b85bb5ed1a6ec80ecfb62d86a5111f7b09d3f","name":"Spam protection, AntiSpam, FireWall by CleanTalk <= 6.82 - Unauthenticated Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/id\/222079a2-20f1-4d53-8420-46ccc50988a8","description":"The Spam protection, AntiSpam, FireWall by CleanTalk plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.82 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-07-27"},{"id":"735c9bd8c1f318d778f41923bb9c32d9ea602fb9","name":"Spam protection, AntiSpam, FireWall by CleanTalk <= 6.82 - Unauthenticated Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/cleantalk-spam-protect\/spam-protection-antispam-firewall-by-cleantalk-682-unauthenticated-stored-cross-site-scripting","description":"The Spam protection, AntiSpam, FireWall by CleanTalk plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.82 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-06-11"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"7.1","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"7.1","severity":"high","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"99aa923fb6feb448fcdd62bb7e55d80301dd916b0c3bf9e6c8723539cfc890ec","name":"Spam protection, Honeypot, Anti-Spam by CleanTalk [cleantalk-spam-protect] < 6.87","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.87","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-77830","name":"CVE-2026-77830","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-77830","description":"[en] The Spam protection, Honeypot, Anti-Spam by CleanTalk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content aria-label Placeholder in all versions up to, and including, 6.86 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with custom-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload is deliverable via unauthenticated comment submission and executes exclusively for non-logged-in visitors; if comment moderation is enabled, an approving moderator must first publish the comment before the script reaches other users.","date":"2026-09-05"},{"id":"09138b26ac06664d3602a1da5b95743a8be9e68d","name":"Spam protection, Honeypot, Anti-Spam by CleanTalk <= 6.86 - Unauthenticated Stored Cross-Site Scripting via Comment Content aria-label Placeholder","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/cleantalk-spam-protect\/spam-protection-honeypot-anti-spam-by-cleantalk-686-unauthenticated-stored-cross-site-scripting-via-comment-content-aria-label-placeholder","description":"The Spam protection, Honeypot, Anti-Spam by CleanTalk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content aria-label Placeholder in all versions up to, and including, 6.86 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with custom-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload is deliverable via unauthenticated comment submission and executes exclusively for non-logged-in visitors; if comment moderation is enabled, an approving moderator must first publish the comment before the script reaches other users.","date":"2026-07-27"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"7.2","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"7.2","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"ea6e3fd0a858a81217eaeb78c4c64993c35ec698f7ec453e6deff219e33ba69b","name":"Spam protection, Honeypot, Anti-Spam by CleanTalk [cleantalk-spam-protect] < 6.87","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.87","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-19855","name":"CVE-2026-19855","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-19855","description":"[en] The CleanTalk WordPress plugin before 6.87 does not prevent unauthenticated, user-supplied comment content from being passed to WordPress's shortcode engine, allowing any visitor to have arbitrary shortcodes registered on the site executed server-side and rendered to every subsequent visitor of the page.","date":"2026-09-09"},{"id":"82cbe01f68568af34036b4f2d19cfd198655e4c9","name":"Spam protection, Honeypot, Anti-Spam by CleanTalk < 6.87 - Unauthenticated Arbitrary Shortcode Execution","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/cleantalk-spam-protect\/spam-protection-honeypot-anti-spam-by-cleantalk-687-unauthenticated-arbitrary-shortcode-execution","description":"The The Spam protection, Honeypot, Anti-Spam by CleanTalk plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to 6.87 (exclusive). This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.","date":"2026-09-04"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"l","a":"n","score":"6.5","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:L\/A:N","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-74","name":"Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')","description":"The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}}]},"updated":"1789642286"}