Extension WordPress
Vulnérabilités CleanTalk Anti-Spam. Spam Firewall & Bot protection
Cette page rassemble les failles publiées pour CleanTalk Anti-Spam. Spam Firewall & Bot protection, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de CleanTalk Anti-Spam. Spam Firewall & Bot protection
14 fiches
CleanTalk Anti-Spam. Spam Firewall & Bot protection < 6.79 – Unauthenticated Stored Cross-Site Scripting
The CleanTalk Anti-Spam. Spam Firewall & Bot protection plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 6.79 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
[*, 6.79)
6.79
11/06/2026
Spam protection, Honeypot, Anti-Spam by CleanTalk <= 6.71 – Authorization Bypass via Reverse DNS (PTR record) Spoofing to Unauthenticated Arbitrary Plugin Installation
The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an authorization bypass via reverse DNS (PTR record) spoofing on the 'checkWithoutToken' function in all versions up to, and…
*-6.71
6.72
14/02/2026
Spam protection, Anti-Spam, FireWall by CleanTalk <= 6.43.2 – Authorization Bypass via Reverse DNS Spoofing to Unauthenticated Arbitrary Plugin Installation
The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an authorization bypass via reverse DNS spoofing on the checkWithoutToken function in all versions up to, and including, 6.43.2.…
*-6.43.2
6.44
25/11/2024
Spam protection, Anti-Spam, FireWall by CleanTalk <= 6.44 – Authorization Bypass due to Missing Empty Value Check to Unauthenticated Arbitrary Plugin Installation
The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an missing empty value check on the 'api_key' value in the 'perform' function in all versions up to, and…
*-6.44
6.45
25/11/2024
Spam protection, AntiSpam, FireWall by CleanTalk <= 6.20 – Cross-Site Request Forgery
The Spam protection, AntiSpam, FireWall by CleanTalk plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.20. This is due to missing or incorrect nonce validation on the apbct_admin__admin_bar__prepare_counters() function. This makes…
*-6.20
6.21
27/12/2023
Spam protection, AntiSpam, FireWall by CleanTalk <= 6.20 – Cross-Site Request Forgery via apbct_settings__update_account_email
The Spam protection, AntiSpam, FireWall by CleanTalk plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.20. This is due to missing or incorrect nonce validation on the apbct_settings__update_account_email function. This makes…
*-6.20
6.21
27/12/2023
Spam protection, AntiSpam, FireWall by CleanTalk <= 6.10 – Missing Authorization
The Spam protection, AntiSpam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on several functions along with nonce disclosure in versions up to, and including,…
*-6.10
6.11
22/06/2023
AntiSpam by CleanTalk <= 5.185 – Authenticated (Administrator+) SQL Injection
The AntiSpam plugin for WordPress is vulnerable to SQL Injection via the ‘ids’ parameter in versions up to, and including, 5.185 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing…
*-5.185
5.185.1
03/10/2022
Spam protection, AntiSpam, FireWall by CleanTalk <= 5.173 – Reflected Cross-Site Scripting
The CleanTalk AntiSpam plugin
*-5.173
5.174.1
30/03/2022
Spam protection, AntiSpam, FireWall by CleanTalk <= 5.173 – Reflected Cross-Site Scripting
The CleanTalk AntiSpam plugin
*-5.173
5.174.1
30/03/2022
Spam protection, AntiSpam, FireWall by CleanTalk <= 5.153.3 – Unauthenticated Blind SQL Injection
It was possible to exploit an Unauthenticated Time-Based Blind SQL Injection vulnerability in the Spam protection, AntiSpam, FireWall by CleanTalk WordPress Plugin before 5.153.4. The update_log function in lib/Cleantalk/ApbctWP/Firewall/SFW.php included a vulnerable query that could be injected via…
*-5.153.3
5.153.4
05/03/2021
Anti-Spam by CleanTalk < 5.149 – Authenticated SQL Injection
Unvalidated input in the Anti-Spam by CleanTalk WordPress plugin, versions before 5.149, lead to multiple authenticated SQL injection vulnerabilities, however, it requires high privilege user (admin+).
[*, 5.149)
5.149
20/11/2020
Spam protection, AntiSpam, FireWall by CleanTalk <= 5.127.3 – Reflected Cross-Site Scripting
The CleanTalk cleantalk-spam-protect plugin before 5.127.4 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via the from or till parameter. The component is: inc/cleantalk-users.php…
*-5.127.3
5.127.4
12/11/2019
Spam protection, AntiSpam, FireWall by CleanTalk < 5.22 – Reflected Cross-Site Scripting
The Spam protection, AntiSpam, FireWall by CleanTalk plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions before 5.22 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…
[*, 5.22)
5.22
25/08/2015
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.