Spam protection, Anti-Spam, FireWall by CleanTalk <= 6.44 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Arbitrary Plugin Installation

2024-11-25 00:00
István Márton

Strategic Overview

Vulnerability Overview

The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an missing empty value check on the 'api_key' value in the 'perform' function in all versions up to, and including, 6.44. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated.

Technical Analysis

REMEDIATION: Update to version 6.45, or a newer patched version --- IDENTIFIER: CWE-703 (Improper Check or Handling of Exceptional Conditions) The product does not properly anticipate or handle exceptional conditions that rarely occur during normal operation of the product.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C