Spam protection, AntiSpam, FireWall by CleanTalk <= 6.82 - Unauthenticated Stored Cross-Site Scripting
high
The Spam protection, AntiSpam, FireWall by CleanTalk plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.82 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that wil...
- CVSS:
- 7.2
- Affected:
- up to 6.82
- Fixed in:
- 6.83
- Disclosed:
- Jul 27, 2026
CVE-2026-65437 on NVD →
CleanTalk Anti-Spam. Spam Firewall & Bot protection < 6.79 - Unauthenticated Stored Cross-Site Scripting
high
The CleanTalk Anti-Spam. Spam Firewall & Bot protection plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 6.79 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whe...
- CVSS:
- 7.2
- Affected:
- up to 6.79
- Fixed in:
- 6.79
- Disclosed:
- Jun 11, 2026
CVE-2026-8071 on NVD →
Spam protection, Honeypot, Anti-Spam by CleanTalk <= 6.71 - Authorization Bypass via Reverse DNS (PTR record) Spoofing to Unauthenticated Arbitrary Plugin Installation
critical
The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an authorization bypass via reverse DNS (PTR record) spoofing on the 'checkWithoutToken' function in all versions up to, and including, 6.71. This makes it possible for unauthent...
- CVSS:
- 9.8
- Affected:
- up to 6.71
- Fixed in:
- 6.72
- Disclosed:
- Feb 14, 2026
CVE-2026-1490 on NVD →
Spam protection, Honeypot, Anti-Spam by CleanTalk [cleantalk-spam-protect] < 6.11
unknown
[en] Missing Authorization vulnerability in СleanTalk - Anti-Spam Protection Spam protection, AntiSpam, FireWall by CleanTalk allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spam protection, AntiSpam, FireWall by CleanTalk: from n/a through 6.10.
- Affected:
- up to 6.11
- Fixed in:
- 6.11
- Disclosed:
- Dec 13, 2024
CVE-2023-33996 on NVD →
Spam protection, Honeypot, Anti-Spam by CleanTalk [cleantalk-spam-protect] < 6.45
unknown
[en] The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an missing empty value check on the 'api_key' value in the 'perform' function in all versions up to, and including, 6.44. This makes it possible for unauthenticated attacker...
- Affected:
- up to 6.45
- Fixed in:
- 6.45
- Disclosed:
- Nov 26, 2024
CVE-2024-10781 on NVD →
Spam protection, Honeypot, Anti-Spam by CleanTalk [cleantalk-spam-protect] < 6.44
unknown
[en] The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an authorization bypass via reverse DNS spoofing on the checkWithoutToken function in all versions up to, and including, 6.43.2. This makes it possible for unauthenticated a...
- Affected:
- up to 6.44
- Fixed in:
- 6.44
- Disclosed:
- Nov 26, 2024
CVE-2024-10542 on NVD →
Spam protection, Anti-Spam, FireWall by CleanTalk <= 6.43.2 - Authorization Bypass via Reverse DNS Spoofing to Unauthenticated Arbitrary Plugin Installation
critical
The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an authorization bypass via reverse DNS spoofing on the checkWithoutToken function in all versions up to, and including, 6.43.2. This makes it possible for unauthenticated attack...
- CVSS:
- 9.8
- Affected:
- up to 6.43.2
- Fixed in:
- 6.44
- Disclosed:
- Nov 25, 2024
CVE-2024-10542 on NVD →
Spam protection, Anti-Spam, FireWall by CleanTalk <= 6.44 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Arbitrary Plugin Installation
high
The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an missing empty value check on the 'api_key' value in the 'perform' function in all versions up to, and including, 6.44. This makes it possible for unauthenticated attackers to...
- CVSS:
- 8.1
- Affected:
- up to 6.44
- Fixed in:
- 6.45
- Disclosed:
- Nov 25, 2024
CVE-2024-10781 on NVD →
Spam protection, Honeypot, Anti-Spam by CleanTalk [cleantalk-spam-protect] < 6.21
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in СleanTalk - Anti-Spam Protection Spam protection, Anti-Spam, FireWall by CleanTalk.This issue affects Spam protection, Anti-Spam, FireWall by CleanTalk: from n/a through 6.20.
- Affected:
- up to 6.21
- Fixed in:
- 6.21
- Disclosed:
- Feb 29, 2024
CVE-2023-51696 on NVD →
Spam protection, Honeypot, Anti-Spam by CleanTalk [cleantalk-spam-protect] < 6.21
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in СleanTalk - Anti-Spam Protection Spam protection, Anti-Spam, FireWall by CleanTalk.This issue affects Spam protection, Anti-Spam, FireWall by CleanTalk: from n/a through 6.20.
- Affected:
- up to 6.21
- Fixed in:
- 6.21
- Disclosed:
- Jan 5, 2024
CVE-2023-51535 on NVD →
Spam protection, AntiSpam, FireWall by CleanTalk <= 6.20 - Cross-Site Request Forgery via apbct_settings__update_account_email
medium
The Spam protection, AntiSpam, FireWall by CleanTalk plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.20. This is due to missing or incorrect nonce validation on the apbct_settings__update_account_email function. This makes it possible for unauthenticated attackers t...
- CVSS:
- 4.3
- Affected:
- up to 6.20
- Fixed in:
- 6.21
- Disclosed:
- Dec 27, 2023
CVE-2023-51696 on NVD →
Spam protection, AntiSpam, FireWall by CleanTalk <= 6.20 - Cross-Site Request Forgery
medium
The Spam protection, AntiSpam, FireWall by CleanTalk plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.20. This is due to missing or incorrect nonce validation on the apbct_admin__admin_bar__prepare_counters() function. This makes it possible for unauthenticated attack...
- CVSS:
- 4.3
- Affected:
- up to 6.20
- Fixed in:
- 6.21
- Disclosed:
- Dec 27, 2023
CVE-2023-51535 on NVD →
Spam protection, AntiSpam, FireWall by CleanTalk <= 6.10 - Missing Authorization
medium
The Spam protection, AntiSpam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on several functions along with nonce disclosure in versions up to, and including, 6.10. This makes it possible for authenticated attackers, with subs...
- CVSS:
- 6.3
- Affected:
- up to 6.10
- Fixed in:
- 6.11
- Disclosed:
- Jun 22, 2023
CVE-2023-33996 on NVD →
Spam protection, Honeypot, Anti-Spam by CleanTalk [cleantalk-spam-protect] < 5.185.1
unknown
[en] The Spam protection, AntiSpam, FireWall by CleanTalk WordPress plugin before 5.185.1 does not validate ids before using them in a SQL statement, which could lead to SQL injection exploitable by high privilege users such as admin
- Affected:
- up to 5.185.1
- Fixed in:
- 5.185.1
- Disclosed:
- Oct 25, 2022
CVE-2022-3302 on NVD →
AntiSpam by CleanTalk <= 5.185 - Authenticated (Administrator+) SQL Injection
high
The AntiSpam plugin for WordPress is vulnerable to SQL Injection via the ‘ids’ parameter in versions up to, and including, 5.185 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrato...
- CVSS:
- 7.2
- Affected:
- up to 5.185
- Fixed in:
- 5.185.1
- Disclosed:
- Oct 3, 2022
CVE-2022-3302 on NVD →
Spam protection, Honeypot, Anti-Spam by CleanTalk [cleantalk-spam-protect] < 5.174.1
unknown
[en] The CleanTalk AntiSpam plugin <= 5.173 for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) via the $_REQUEST['page'] parameter in`/lib/Cleantalk/ApbctWP/FindSpam/ListTable/Users.php`
- Affected:
- up to 5.174.1
- Fixed in:
- 5.174.1
- Disclosed:
- Apr 19, 2022
CVE-2022-28222 on NVD →
Spam protection, Honeypot, Anti-Spam by CleanTalk [cleantalk-spam-protect] < 5.174.1
unknown
[en] The CleanTalk AntiSpam plugin <= 5.173 for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) via the $_REQUEST['page'] parameter in`/lib/Cleantalk/ApbctWP/FindSpam/ListTable/Comments.php`
- Affected:
- up to 5.174.1
- Fixed in:
- 5.174.1
- Disclosed:
- Apr 19, 2022
CVE-2022-28221 on NVD →
Spam protection, AntiSpam, FireWall by CleanTalk <= 5.173 - Reflected Cross-Site Scripting
medium
The CleanTalk AntiSpam plugin <= 5.173 for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) via the $_REQUEST['page'] parameter in the /lib/Cleantalk/ApbctWP/FindSpam/ListTable/Users.php file.
- CVSS:
- 6.1
- Affected:
- up to 5.173
- Fixed in:
- 5.174.1
- Disclosed:
- Mar 30, 2022
CVE-2022-28222 on NVD →
Spam protection, AntiSpam, FireWall by CleanTalk <= 5.173 - Reflected Cross-Site Scripting
medium
The CleanTalk AntiSpam plugin <= 5.173 for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) via the $_REQUEST['page'] parameter found in the /lib/Cleantalk/ApbctWP/FindSpam/ListTable/Comments.php file.
- CVSS:
- 6.1
- Affected:
- up to 5.173
- Fixed in:
- 5.174.1
- Disclosed:
- Mar 30, 2022
CVE-2022-28221 on NVD →
Spam protection, Honeypot, Anti-Spam by CleanTalk [cleantalk-spam-protect] < 5.153.4
unknown
[en] It was possible to exploit an Unauthenticated Time-Based Blind SQL Injection vulnerability in the Spam protection, AntiSpam, FireWall by CleanTalk WordPress Plugin before 5.153.4. The update_log function in lib/Cleantalk/ApbctWP/Firewall/SFW.php included a vulnerable query that could be injected via the User-Agent...
- Affected:
- up to 5.153.4
- Fixed in:
- 5.153.4
- Disclosed:
- May 17, 2021
CVE-2021-24295 on NVD →
Spam protection, Honeypot, Anti-Spam by CleanTalk [cleantalk-spam-protect] < 5.149
unknown
[en] Unvalidated input in the Anti-Spam by CleanTalk WordPress plugin, versions before 5.149, lead to multiple authenticated SQL injection vulnerabilities, however, it requires high privilege user (admin+).
- Affected:
- up to 5.149
- Fixed in:
- 5.149
- Disclosed:
- Mar 18, 2021
CVE-2021-24131 on NVD →
Spam protection, AntiSpam, FireWall by CleanTalk <= 5.153.3 - Unauthenticated Blind SQL Injection
high
It was possible to exploit an Unauthenticated Time-Based Blind SQL Injection vulnerability in the Spam protection, AntiSpam, FireWall by CleanTalk WordPress Plugin before 5.153.4. The update_log function in lib/Cleantalk/ApbctWP/Firewall/SFW.php included a vulnerable query that could be injected via the User-Agent Head...
- CVSS:
- 7.5
- Affected:
- up to 5.153.3
- Fixed in:
- 5.153.4
- Disclosed:
- Mar 5, 2021
CVE-2021-24295 on NVD →
Anti-Spam by CleanTalk < 5.149 - Authenticated SQL Injection
high
Unvalidated input in the Anti-Spam by CleanTalk WordPress plugin, versions before 5.149, lead to multiple authenticated SQL injection vulnerabilities, however, it requires high privilege user (admin+).
- CVSS:
- 7.2
- Affected:
- up to 5.149
- Fixed in:
- 5.149
- Disclosed:
- Nov 20, 2020
CVE-2021-24131 on NVD →
Spam protection, Honeypot, Anti-Spam by CleanTalk [cleantalk-spam-protect] < 5.149
unknown
Multiple Authenticated SQL Injection (SQLi) vulnerabilities found by Nguyen Anh Tien in WordPress Anti-Spam by CleanTalk plugin (versions <= 5.148).
- Affected:
- up to 5.149
- Fixed in:
- 5.149
- Disclosed:
- Nov 20, 2020
Spam protection, Honeypot, Anti-Spam by CleanTalk [cleantalk-spam-protect] < 5.127.4
unknown
[en] The CleanTalk cleantalk-spam-protect plugin before 5.127.4 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via the from or till parameter. The component is: inc/cleantalk-users.php and inc/cleantalk-comments.php. The attack v...
- Affected:
- up to 5.127.4
- Fixed in:
- 5.127.4
- Disclosed:
- Nov 13, 2019
CVE-2019-17515 on NVD →
Spam protection, AntiSpam, FireWall by CleanTalk <= 5.127.3 - Reflected Cross-Site Scripting
medium
The CleanTalk cleantalk-spam-protect plugin before 5.127.4 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via the from or till parameter. The component is: inc/cleantalk-users.php and inc/cleantalk-comments.php. The attack vector...
- CVSS:
- 6.1
- Affected:
- up to 5.127.3
- Fixed in:
- 5.127.4
- Disclosed:
- Nov 12, 2019
CVE-2019-17515 on NVD →
Spam protection, AntiSpam, FireWall by CleanTalk < 5.22 - Reflected Cross-Site Scripting
medium
The Spam protection, AntiSpam, FireWall by CleanTalk plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions before 5.22 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pag...
- CVSS:
- 6.1
- Affected:
- up to 5.22
- Fixed in:
- 5.22
- Disclosed:
- Aug 25, 2015
Spam protection, Honeypot, Anti-Spam by CleanTalk [cleantalk-spam-protect] < 5.22
unknown
Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.
Update the plugin.
- Affected:
- up to 5.22
- Fixed in:
- 5.22
- Disclosed:
- Aug 25, 2015
Spam protection, Honeypot, Anti-Spam by CleanTalk [cleantalk-spam-protect] < 5.22
unknown
The Spam protection, AntiSpam, FireWall by CleanTalk plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions before 5.22 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pag...
- Affected:
- up to 5.22
- Fixed in:
- 5.22
- Disclosed:
- Aug 25, 2015
Spam protection, Honeypot, Anti-Spam by CleanTalk [cleantalk-spam-protect] < 5.22
unknown
The Spam protection, AntiSpam, FireWall by CleanTalk WordPress plugin was affected by an Unauthenticated Reflected Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 5.22
- Fixed in:
- 5.22