CVE-2024-10542

CRITICAL

CleanTalk Spam Protection <=6.43.2 - Unauthenticated Plugin Installation via DNS Spoofing

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-10542. PoCs published by ubaydev.

AI-analyzed exploit summary The repository provides a functional proof-of-concept for CVE-2024-10542, demonstrating an authorization bypass via reverse DNS spoofing in the CleanTalk WordPress plugin. The PoC includes a crafted HTTP request to install arbitrary plugins, leveraging a host file manipulation to spoof the 'cleantalk.org' domain.

Description

The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an authorization bypass via reverse DNS spoofing on the checkWithoutToken function in all versions up to, and including, 6.43.2. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated.

Exploits (1)

nomisec WORKING POC 2 stars
by ubaydev · poc
https://github.com/ubaydev/CVE-2024-10542

The repository provides a functional proof-of-concept for CVE-2024-10542, demonstrating an authorization bypass via reverse DNS spoofing in the CleanTalk WordPress plugin. The PoC includes a crafted HTTP request to install arbitrary plugins, leveraging a host file manipulation to spoof the 'cleantalk.org' domain.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Spam protection, AntiSpam, FireWall by CleanTalk Plugin <= 6.43.2
No auth needed
Prerequisites: Ability to modify the host file to spoof 'cleantalk.org' · Network access to the target WordPress site
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Scores

CVSS v3 9.8
EPSS 0.1524
EPSS Percentile 96.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-862
Status published
Products (2)
cleantalk/anti-spam < 6.44
cleantalk/Spam protection, Honeypot, Anti-Spam by CleanTalk < 6.43.2
Published Nov 26, 2024
Tracked Since Feb 18, 2026