WordPress Woes: CleanTalk Plugin Vulnerabilities Leave 100,000 Sites Open to Attack!

CleanTalk’s anti-spam plugin for WordPress had two major vulnerabilities that could let hackers remotely install sketchy plugins. These flaws, affecting over 200,000 users, were resolved with updates. If you have the “Spam protection, Anti-Spam, FireWall by CleanTalk” plugin, update to version 6.45 pronto to avoid unwanted surprises!

Pro Dashboard

Hot Take:

WordPress users, time to put on your digital armor and update those plugins! CleanTalk’s anti-spam plugin is currently playing the role of the unwelcome guest, letting in all sorts of party crashers. It’s a classic case of “who watches the watchmen?” when your spam protector needs protecting. Better patch up, or your website might become a hacker’s playground!

Key Points:

  • Two critical vulnerabilities identified in CleanTalk’s anti-spam plugin for WordPress.
  • Vulnerabilities tracked as CVE-2024-10542 and CVE-2024-10781 with a CVSS score of 9.8.
  • Flaws could allow remote attackers to install and activate arbitrary plugins, potentially leading to remote code execution (RCE).
  • Over 200,000 active installations of the affected plugin, with approximately half still vulnerable.
  • Users are advised to update to version 6.45 for fixes to both security issues.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?