nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-13365 CVE-2024-13365
CRITICAL
Security & Malware scan by CleanTalk <= 2.149 - Unauthenticated Arbitrary File Upload
Record summary
CVE-2024-13365 has a selected CVSS score of 9.8 (critical).
Description
The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to arbitrary file uploads due to the plugin uploading and extracting .zip archives when scanning them for malware through the checkUploadedArchive() function in all versions up to, and including, 2.149. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · May 5, 2026 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 12, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Login Security, FireWall, Malware removal by CleanTalkBrowse cleantalk / Login Security, FireWall, Malware removal by CleanTalkDefault status: unaffected | CVE List | Through 2.149 | affected |
security_\&_malware_scanBrowse cleantalk / security_\&_malware_scan | VulnCheck | Version data not supplied | |
References
3plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/changeset/3229205/security-malware-firewall wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/9fa30fa2-6c42-4e5f-a0b5-8711ce5d8121?source=cve