plugin

Cleantalk Spam Protect Vulnerabilities

30 known security issues reported for the Cleantalk Spam Protect WordPress plugin. Most recent disclosed Jul 27, 2026.

2 critical 6 high 7 medium

Running Cleantalk Spam Protect on your site? Check whether your installed version is affected.

Scan your site free

Spam protection, AntiSpam, FireWall by CleanTalk <= 6.82 - Unauthenticated Stored Cross-Site Scripting

high

The Spam protection, AntiSpam, FireWall by CleanTalk plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.82 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that wil...

CVSS:
7.2
Affected:
up to 6.82
Fixed in:
6.83
Disclosed:
Jul 27, 2026

CVE-2026-65437 on NVD →

CleanTalk Anti-Spam. Spam Firewall & Bot protection < 6.79 - Unauthenticated Stored Cross-Site Scripting

high

The CleanTalk Anti-Spam. Spam Firewall & Bot protection plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 6.79 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whe...

CVSS:
7.2
Affected:
up to 6.79
Fixed in:
6.79
Disclosed:
Jun 11, 2026

CVE-2026-8071 on NVD →

Spam protection, Honeypot, Anti-Spam by CleanTalk <= 6.71 - Authorization Bypass via Reverse DNS (PTR record) Spoofing to Unauthenticated Arbitrary Plugin Installation

critical

The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an authorization bypass via reverse DNS (PTR record) spoofing on the 'checkWithoutToken' function in all versions up to, and including, 6.71. This makes it possible for unauthent...

CVSS:
9.8
Affected:
up to 6.71
Fixed in:
6.72
Disclosed:
Feb 14, 2026

CVE-2026-1490 on NVD →

Spam protection, Honeypot, Anti-Spam by CleanTalk [cleantalk-spam-protect] < 6.11

unknown

[en] Missing Authorization vulnerability in СleanTalk - Anti-Spam Protection Spam protection, AntiSpam, FireWall by CleanTalk allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spam protection, AntiSpam, FireWall by CleanTalk: from n/a through 6.10.

Affected:
up to 6.11
Fixed in:
6.11
Disclosed:
Dec 13, 2024

CVE-2023-33996 on NVD →

Spam protection, Honeypot, Anti-Spam by CleanTalk [cleantalk-spam-protect] < 6.45

unknown

[en] The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an missing empty value check on the 'api_key' value in the 'perform' function in all versions up to, and including, 6.44. This makes it possible for unauthenticated attacker...

Affected:
up to 6.45
Fixed in:
6.45
Disclosed:
Nov 26, 2024

CVE-2024-10781 on NVD →

Spam protection, Honeypot, Anti-Spam by CleanTalk [cleantalk-spam-protect] < 6.44

unknown

[en] The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an authorization bypass via reverse DNS spoofing on the checkWithoutToken function in all versions up to, and including, 6.43.2. This makes it possible for unauthenticated a...

Affected:
up to 6.44
Fixed in:
6.44
Disclosed:
Nov 26, 2024

CVE-2024-10542 on NVD →

Spam protection, Anti-Spam, FireWall by CleanTalk <= 6.43.2 - Authorization Bypass via Reverse DNS Spoofing to Unauthenticated Arbitrary Plugin Installation

critical

The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an authorization bypass via reverse DNS spoofing on the checkWithoutToken function in all versions up to, and including, 6.43.2. This makes it possible for unauthenticated attack...

CVSS:
9.8
Affected:
up to 6.43.2
Fixed in:
6.44
Disclosed:
Nov 25, 2024

CVE-2024-10542 on NVD →

Spam protection, Anti-Spam, FireWall by CleanTalk <= 6.44 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Arbitrary Plugin Installation

high

The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an missing empty value check on the 'api_key' value in the 'perform' function in all versions up to, and including, 6.44. This makes it possible for unauthenticated attackers to...

CVSS:
8.1
Affected:
up to 6.44
Fixed in:
6.45
Disclosed:
Nov 25, 2024

CVE-2024-10781 on NVD →

Spam protection, Honeypot, Anti-Spam by CleanTalk [cleantalk-spam-protect] < 6.21

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in СleanTalk - Anti-Spam Protection Spam protection, Anti-Spam, FireWall by CleanTalk.This issue affects Spam protection, Anti-Spam, FireWall by CleanTalk: from n/a through 6.20.

Affected:
up to 6.21
Fixed in:
6.21
Disclosed:
Feb 29, 2024

CVE-2023-51696 on NVD →

Spam protection, Honeypot, Anti-Spam by CleanTalk [cleantalk-spam-protect] < 6.21

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in СleanTalk - Anti-Spam Protection Spam protection, Anti-Spam, FireWall by CleanTalk.This issue affects Spam protection, Anti-Spam, FireWall by CleanTalk: from n/a through 6.20.

Affected:
up to 6.21
Fixed in:
6.21
Disclosed:
Jan 5, 2024

CVE-2023-51535 on NVD →

Spam protection, AntiSpam, FireWall by CleanTalk <= 6.20 - Cross-Site Request Forgery via apbct_settings__update_account_email

medium

The Spam protection, AntiSpam, FireWall by CleanTalk plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.20. This is due to missing or incorrect nonce validation on the apbct_settings__update_account_email function. This makes it possible for unauthenticated attackers t...

CVSS:
4.3
Affected:
up to 6.20
Fixed in:
6.21
Disclosed:
Dec 27, 2023

CVE-2023-51696 on NVD →

Spam protection, AntiSpam, FireWall by CleanTalk <= 6.20 - Cross-Site Request Forgery

medium

The Spam protection, AntiSpam, FireWall by CleanTalk plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.20. This is due to missing or incorrect nonce validation on the apbct_admin__admin_bar__prepare_counters() function. This makes it possible for unauthenticated attack...

CVSS:
4.3
Affected:
up to 6.20
Fixed in:
6.21
Disclosed:
Dec 27, 2023

CVE-2023-51535 on NVD →

Spam protection, AntiSpam, FireWall by CleanTalk <= 6.10 - Missing Authorization

medium

The Spam protection, AntiSpam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on several functions along with nonce disclosure in versions up to, and including, 6.10. This makes it possible for authenticated attackers, with subs...

CVSS:
6.3
Affected:
up to 6.10
Fixed in:
6.11
Disclosed:
Jun 22, 2023

CVE-2023-33996 on NVD →

Spam protection, Honeypot, Anti-Spam by CleanTalk [cleantalk-spam-protect] < 5.185.1

unknown

[en] The Spam protection, AntiSpam, FireWall by CleanTalk WordPress plugin before 5.185.1 does not validate ids before using them in a SQL statement, which could lead to SQL injection exploitable by high privilege users such as admin

Affected:
up to 5.185.1
Fixed in:
5.185.1
Disclosed:
Oct 25, 2022

CVE-2022-3302 on NVD →

AntiSpam by CleanTalk <= 5.185 - Authenticated (Administrator+) SQL Injection

high

The AntiSpam plugin for WordPress is vulnerable to SQL Injection via the ‘ids’ parameter in versions up to, and including, 5.185 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrato...

CVSS:
7.2
Affected:
up to 5.185
Fixed in:
5.185.1
Disclosed:
Oct 3, 2022

CVE-2022-3302 on NVD →

Spam protection, Honeypot, Anti-Spam by CleanTalk [cleantalk-spam-protect] < 5.174.1

unknown

[en] The CleanTalk AntiSpam plugin <= 5.173 for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) via the $_REQUEST['page'] parameter in`/lib/Cleantalk/ApbctWP/FindSpam/ListTable/Users.php`

Affected:
up to 5.174.1
Fixed in:
5.174.1
Disclosed:
Apr 19, 2022

CVE-2022-28222 on NVD →

Spam protection, Honeypot, Anti-Spam by CleanTalk [cleantalk-spam-protect] < 5.174.1

unknown

[en] The CleanTalk AntiSpam plugin <= 5.173 for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) via the $_REQUEST['page'] parameter in`/lib/Cleantalk/ApbctWP/FindSpam/ListTable/Comments.php`

Affected:
up to 5.174.1
Fixed in:
5.174.1
Disclosed:
Apr 19, 2022

CVE-2022-28221 on NVD →

Spam protection, AntiSpam, FireWall by CleanTalk <= 5.173 - Reflected Cross-Site Scripting

medium

The CleanTalk AntiSpam plugin <= 5.173 for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) via the $_REQUEST['page'] parameter in the /lib/Cleantalk/ApbctWP/FindSpam/ListTable/Users.php file.

CVSS:
6.1
Affected:
up to 5.173
Fixed in:
5.174.1
Disclosed:
Mar 30, 2022

CVE-2022-28222 on NVD →

Spam protection, AntiSpam, FireWall by CleanTalk <= 5.173 - Reflected Cross-Site Scripting

medium

The CleanTalk AntiSpam plugin <= 5.173 for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) via the $_REQUEST['page'] parameter found in the /lib/Cleantalk/ApbctWP/FindSpam/ListTable/Comments.php file.

CVSS:
6.1
Affected:
up to 5.173
Fixed in:
5.174.1
Disclosed:
Mar 30, 2022

CVE-2022-28221 on NVD →

Spam protection, Honeypot, Anti-Spam by CleanTalk [cleantalk-spam-protect] < 5.153.4

unknown

[en] It was possible to exploit an Unauthenticated Time-Based Blind SQL Injection vulnerability in the Spam protection, AntiSpam, FireWall by CleanTalk WordPress Plugin before 5.153.4. The update_log function in lib/Cleantalk/ApbctWP/Firewall/SFW.php included a vulnerable query that could be injected via the User-Agent...

Affected:
up to 5.153.4
Fixed in:
5.153.4
Disclosed:
May 17, 2021

CVE-2021-24295 on NVD →

Spam protection, Honeypot, Anti-Spam by CleanTalk [cleantalk-spam-protect] < 5.149

unknown

[en] Unvalidated input in the Anti-Spam by CleanTalk WordPress plugin, versions before 5.149, lead to multiple authenticated SQL injection vulnerabilities, however, it requires high privilege user (admin+).

Affected:
up to 5.149
Fixed in:
5.149
Disclosed:
Mar 18, 2021

CVE-2021-24131 on NVD →

Spam protection, AntiSpam, FireWall by CleanTalk <= 5.153.3 - Unauthenticated Blind SQL Injection

high

It was possible to exploit an Unauthenticated Time-Based Blind SQL Injection vulnerability in the Spam protection, AntiSpam, FireWall by CleanTalk WordPress Plugin before 5.153.4. The update_log function in lib/Cleantalk/ApbctWP/Firewall/SFW.php included a vulnerable query that could be injected via the User-Agent Head...

CVSS:
7.5
Affected:
up to 5.153.3
Fixed in:
5.153.4
Disclosed:
Mar 5, 2021

CVE-2021-24295 on NVD →

Anti-Spam by CleanTalk < 5.149 - Authenticated SQL Injection

high

Unvalidated input in the Anti-Spam by CleanTalk WordPress plugin, versions before 5.149, lead to multiple authenticated SQL injection vulnerabilities, however, it requires high privilege user (admin+).

CVSS:
7.2
Affected:
up to 5.149
Fixed in:
5.149
Disclosed:
Nov 20, 2020

CVE-2021-24131 on NVD →

Spam protection, Honeypot, Anti-Spam by CleanTalk [cleantalk-spam-protect] < 5.149

unknown

Multiple Authenticated SQL Injection (SQLi) vulnerabilities found by Nguyen Anh Tien in WordPress Anti-Spam by CleanTalk plugin (versions <= 5.148).

Affected:
up to 5.149
Fixed in:
5.149
Disclosed:
Nov 20, 2020

Spam protection, Honeypot, Anti-Spam by CleanTalk [cleantalk-spam-protect] < 5.127.4

unknown

[en] The CleanTalk cleantalk-spam-protect plugin before 5.127.4 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via the from or till parameter. The component is: inc/cleantalk-users.php and inc/cleantalk-comments.php. The attack v...

Affected:
up to 5.127.4
Fixed in:
5.127.4
Disclosed:
Nov 13, 2019

CVE-2019-17515 on NVD →

Spam protection, AntiSpam, FireWall by CleanTalk <= 5.127.3 - Reflected Cross-Site Scripting

medium

The CleanTalk cleantalk-spam-protect plugin before 5.127.4 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via the from or till parameter. The component is: inc/cleantalk-users.php and inc/cleantalk-comments.php. The attack vector...

CVSS:
6.1
Affected:
up to 5.127.3
Fixed in:
5.127.4
Disclosed:
Nov 12, 2019

CVE-2019-17515 on NVD →

Spam protection, AntiSpam, FireWall by CleanTalk < 5.22 - Reflected Cross-Site Scripting

medium

The Spam protection, AntiSpam, FireWall by CleanTalk plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions before 5.22 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pag...

CVSS:
6.1
Affected:
up to 5.22
Fixed in:
5.22
Disclosed:
Aug 25, 2015

Spam protection, Honeypot, Anti-Spam by CleanTalk [cleantalk-spam-protect] < 5.22

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 5.22
Fixed in:
5.22
Disclosed:
Aug 25, 2015

Spam protection, Honeypot, Anti-Spam by CleanTalk [cleantalk-spam-protect] < 5.22

unknown

The Spam protection, AntiSpam, FireWall by CleanTalk plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions before 5.22 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pag...

Affected:
up to 5.22
Fixed in:
5.22
Disclosed:
Aug 25, 2015

Spam protection, Honeypot, Anti-Spam by CleanTalk [cleantalk-spam-protect] < 5.22

unknown

The Spam protection, AntiSpam, FireWall by CleanTalk WordPress plugin was affected by an Unauthenticated Reflected Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 5.22
Fixed in:
5.22

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database