Extension WordPress

Vulnérabilités CleanTalk Anti-Spam. Spam Firewall & Bot protection

Cette page rassemble les failles publiées pour CleanTalk Anti-Spam. Spam Firewall & Bot protection, leurs plages de versions affectées et les correctifs signalés dans la base locale.

14Vulnérabilités
2Critiques
14Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de CleanTalk Anti-Spam. Spam Firewall & Bot protection

14 fiches

CVE-2026-8071 Élevée · 7,2
CleanTalk Anti-Spam. Spam Firewall & Bot protection

CleanTalk Anti-Spam. Spam Firewall & Bot protection < 6.79 – Unauthenticated Stored Cross-Site Scripting

The CleanTalk Anti-Spam. Spam Firewall & Bot protection plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 6.79 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…

Versions affectées

[*, 6.79)

Correctif

6.79

Publication

11/06/2026

CVE-2026-1490 Critique · 9,8
CleanTalk Anti-Spam. Spam Firewall & Bot protection

Spam protection, Honeypot, Anti-Spam by CleanTalk <= 6.71 – Authorization Bypass via Reverse DNS (PTR record) Spoofing to Unauthenticated Arbitrary Plugin Installation

The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an authorization bypass via reverse DNS (PTR record) spoofing on the 'checkWithoutToken' function in all versions up to, and…

Versions affectées

*-6.71

Correctif

6.72

Publication

14/02/2026

CVE-2024-10542 Critique · 9,8
CleanTalk Anti-Spam. Spam Firewall & Bot protection

Spam protection, Anti-Spam, FireWall by CleanTalk <= 6.43.2 – Authorization Bypass via Reverse DNS Spoofing to Unauthenticated Arbitrary Plugin Installation

The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an authorization bypass via reverse DNS spoofing on the checkWithoutToken function in all versions up to, and including, 6.43.2.…

Versions affectées

*-6.43.2

Correctif

6.44

Publication

25/11/2024

CVE-2024-10781 Élevée · 8,1
CleanTalk Anti-Spam. Spam Firewall & Bot protection

Spam protection, Anti-Spam, FireWall by CleanTalk <= 6.44 – Authorization Bypass due to Missing Empty Value Check to Unauthenticated Arbitrary Plugin Installation

The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an missing empty value check on the 'api_key' value in the 'perform' function in all versions up to, and…

Versions affectées

*-6.44

Correctif

6.45

Publication

25/11/2024

CVE-2023-51535 Moyenne · 4,3
CleanTalk Anti-Spam. Spam Firewall & Bot protection

Spam protection, AntiSpam, FireWall by CleanTalk <= 6.20 – Cross-Site Request Forgery

The Spam protection, AntiSpam, FireWall by CleanTalk plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.20. This is due to missing or incorrect nonce validation on the apbct_admin__admin_bar__prepare_counters() function. This makes…

Versions affectées

*-6.20

Correctif

6.21

Publication

27/12/2023

CVE-2023-51696 Moyenne · 4,3
CleanTalk Anti-Spam. Spam Firewall & Bot protection

Spam protection, AntiSpam, FireWall by CleanTalk <= 6.20 – Cross-Site Request Forgery via apbct_settings__update_account_email

The Spam protection, AntiSpam, FireWall by CleanTalk plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.20. This is due to missing or incorrect nonce validation on the apbct_settings__update_account_email function. This makes…

Versions affectées

*-6.20

Correctif

6.21

Publication

27/12/2023

CVE-2023-33996 Moyenne · 6,3
CleanTalk Anti-Spam. Spam Firewall & Bot protection

Spam protection, AntiSpam, FireWall by CleanTalk <= 6.10 – Missing Authorization

The Spam protection, AntiSpam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on several functions along with nonce disclosure in versions up to, and including,…

Versions affectées

*-6.10

Correctif

6.11

Publication

22/06/2023

CVE-2022-3302 Élevée · 7,2
CleanTalk Anti-Spam. Spam Firewall & Bot protection

AntiSpam by CleanTalk <= 5.185 – Authenticated (Administrator+) SQL Injection

The AntiSpam plugin for WordPress is vulnerable to SQL Injection via the ‘ids’ parameter in versions up to, and including, 5.185 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing…

Versions affectées

*-5.185

Correctif

5.185.1

Publication

03/10/2022

CVE-2021-24295 Élevée · 7,5
CleanTalk Anti-Spam. Spam Firewall & Bot protection

Spam protection, AntiSpam, FireWall by CleanTalk <= 5.153.3 – Unauthenticated Blind SQL Injection

It was possible to exploit an Unauthenticated Time-Based Blind SQL Injection vulnerability in the Spam protection, AntiSpam, FireWall by CleanTalk WordPress Plugin before 5.153.4. The update_log function in lib/Cleantalk/ApbctWP/Firewall/SFW.php included a vulnerable query that could be injected via…

Versions affectées

*-5.153.3

Correctif

5.153.4

Publication

05/03/2021

CVE-2019-17515 Moyenne · 6,1
CleanTalk Anti-Spam. Spam Firewall & Bot protection

Spam protection, AntiSpam, FireWall by CleanTalk <= 5.127.3 – Reflected Cross-Site Scripting

The CleanTalk cleantalk-spam-protect plugin before 5.127.4 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via the from or till parameter. The component is: inc/cleantalk-users.php…

Versions affectées

*-5.127.3

Correctif

5.127.4

Publication

12/11/2019

Vulnérabilité Moyenne · 6,1
CleanTalk Anti-Spam. Spam Firewall & Bot protection

Spam protection, AntiSpam, FireWall by CleanTalk < 5.22 – Reflected Cross-Site Scripting

The Spam protection, AntiSpam, FireWall by CleanTalk plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions before 5.22 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…

Versions affectées

[*, 5.22)

Correctif

5.22

Publication

25/08/2015

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités