Extension WordPress
Vulnérabilités Security Plugin, Firewall & Malware Scanner with Auto Removal
Cette page rassemble les failles publiées pour Security Plugin, Firewall & Malware Scanner with Auto Removal, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Security Plugin, Firewall & Malware Scanner with Auto Removal
5 fiches
Login Security, FireWall, Malware removal by CleanTalk <= 2.168 – Unauthenticated Stored Cross-Site Scripting via Page URL
The Login Security, FireWall, Malware removal by CleanTalk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the page URL in all versions up to, and including, 2.168 due to insufficient input sanitization and output escaping. This…
*-2.168
2.169
08/12/2025
Security & Malware scan by CleanTalk <= 2.149 – Unauthenticated Arbitrary File Upload
The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to arbitrary file uploads due to the plugin uploading and extracting .zip archives when scanning them for malware through the checkUploadedArchive() function in all versions up…
*-2.149
2.150
11/02/2025
Security & Malware scan by CleanTalk <= 2.145 – Authorization Bypass via Reverse DNS Spoofing to Unauthenticated SQL Injection
The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to unauthorized SQL Injection due to an authorization bypass via reverse DNS spoofing on the checkWithoutToken function in all versions up to, and including, 2.145, as…
*-2.145
2.145.1
25/11/2024
Security & Malware scan by CleanTalk <= 2.120 – IP Spoofing to Protection Mechanism Bypass
The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.120. This is due to insufficient restrictions on where the IP Address information is being retrieved…
*-2.120
2.121
06/11/2023
Security & Malware scan by CleanTalk <= 2.50 – Missing Authorization
The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to unauthorized user interaction in versions up to, and including, 2.50. This is due to missing capability checks on several AJAX actions and nonce disclosure in…
*-2.50
2.51
06/07/2020
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.