CVE-2024-10542
CRITICALCleanTalk Spam Protection <=6.43.2 - Unauthenticated Plugin Installation via DNS Spoofing
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-10542. PoCs published by ubaydev.
AI-analyzed exploit summary The repository provides a functional proof-of-concept for CVE-2024-10542, demonstrating an authorization bypass via reverse DNS spoofing in the CleanTalk WordPress plugin. The PoC includes a crafted HTTP request to install arbitrary plugins, leveraging a host file manipulation to spoof the 'cleantalk.org' domain.
Description
The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an authorization bypass via reverse DNS spoofing on the checkWithoutToken function in all versions up to, and including, 6.43.2. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated.
Exploits (1)
The repository provides a functional proof-of-concept for CVE-2024-10542, demonstrating an authorization bypass via reverse DNS spoofing in the CleanTalk WordPress plugin. The PoC includes a crafted HTTP request to install arbitrary plugins, leveraging a host file manipulation to spoof the 'cleantalk.org' domain.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H