Record summary

CVE-2024-13365 has a selected CVSS score of 9.8 (critical).

Description

The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to arbitrary file uploads due to the plugin uploading and extracting .zip archives when scanning them for malware through the checkUploadedArchive() function in all versions up to, and including, 2.149. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · May 5, 2026 · VulnCheck
Reported exploitation
Observed · VulnCheck

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 12, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Login Security, FireWall, Malware removal by CleanTalk

Browse cleantalk / Login Security, FireWall, Malware removal by CleanTalk

Default status: unaffected

CVE ListThrough 2.149affected
VulnCheckVersion data not supplied

References

3