9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an authorization bypass via reverse DNS (PTR record) spoofing on the 'checkWithoutToken' function in all versions up to, and including, 6.71. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated. Note: This is only exploitable on sites with an invalid API key.
AI Analysis
Authorization bypass via reverse DNS spoofing allows unauthenticated attackers to install arbitrary plugins, potentially leading to remote code execution.
Basic Information
ID
CVE-2026-1490
Source
Wordfence
Published
Feb 15, 2026 at 02:22
Affected Product
Vendor
cleantalk
Product
Spam protection, Honeypot, Anti-Spam by CleanTalk
Version
*
Affected Versions
cleantalk Spam protection, Honeypot, Anti-Spam by CleanTalk *
CWE Classification
AI Assessment
AI Score
9.8 / 10
AI Severity
Critical
Vendor
CleanTalk
Product
Spam protection, Honeypot, Anti-Spam by CleanTalk
Version
6.71
References
- www.wordfence.com /threat-intel/vulnerabilities/id/cb603be6-4a12-49e1-b8cc-b2062eb97f16
- plugins.trac.wordpress.org /browser/cleantalk-spam-protect/trunk/lib/Cleantalk/ApbctWP/RemoteCalls.php
- plugins.trac.wordpress.org /browser/cleantalk-spam-protect/trunk/lib/Cleantalk/Common/Helper.php
- plugins.trac.wordpress.org /changeset/3454488/cleantalk-spam-protect