WordPress Plugin Flaws: Is Your Site a Sitting Duck for Hackers?
Two security flaws in the Spam protection, Anti-Spam, FireWall plugin could let attackers install malicious plugins on WordPress sites. Users should update to the latest version to avoid potential threats.

Hot Take:
It seems like the Spam protection, Anti-Spam, and FireWall plugin for WordPress might need its own spam filter to protect against the spammy attacks it unintentionally invited. Who knew that a plugin designed to block spam would become a red carpet for malicious software? Maybe it’s time to give the plugin a better mirror to check itself out before crashing the WordPress party with some uninvited guests!
Key Points:
- Two critical vulnerabilities identified as CVE-2024-10542 and CVE-2024-10781.
- These flaws impact CleanTalk’s Spam protection, Anti-Spam, FireWall plugin on WordPress.
- Both vulnerabilities enable unauthorized arbitrary plugin installation and potential remote code execution.
- Over 200,000 WordPress sites are at risk unless updated to versions 6.44 or 6.45.
- Sucuri warns of campaigns exploiting compromised sites to deliver malicious redirects and malware.
Already a member? Log in here