Spam protection, Honeypot, Anti-Spam by CleanTalk <= 6.71 - Authorization Bypass via Reverse DNS (PTR record) Spoofing to Unauthenticated Arbitrary Plugin Installation
Anti Spam for Contact Forms, Comments & Online Stores – CleanTalk
Minimum safe version
6.72
Update to 6.72 or later to address 16 fixable vulnerabilities
CVE-2024-10781
CVE-2024-10542
WordPress Spam protection, AntiSpam, FireWall by CleanTalk Plugin <= 6.20 is vulnerable to Cross Site Request Forgery (CSRF)
WordPress Spam protection, AntiSpam, FireWall by CleanTalk Plugin <= 6.20 is vulnerable to Cross Site Request Forgery (CSRF)
CVE-2023-33996
Spam protection, AntiSpam, FireWall by CleanTalk < 5.22 - Reflected Cross-Site Scripting
Anti-Spam by CleanTalk < 5.22 - Unauthenticated Reflected Cross-Site Scripting (XSS)
CVE-2022-3302
WordPress Spam Protection Plugin <= 5.21 - Cross Site Scripting
WordPress Anti-Spam by CleanTalk plugin <= 5.148 - Multiple Authenticated SQL Injection (SQLi) vulnerabilities
CVE-2022-28221
CVE-2022-28222
WordPress Spam protection, AntiSpam, FireWall by CleanTalk plugin <=5.127.3 - Cross-Site Scripting (XSS) vulnerability
CVE-2021-24131
CVE-2021-24295