CVE-2026-1490
CRITICALCleanTalk Spam Protection <= 6.71 - Unauthenticated Arbitrary Plugin Installation via DNS Spoofing
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2026-1490. PoCs published by XiaomingX, comthompson30.
AI-analyzed exploit summary The repository contains a functional SQL injection exploit for WordPress Quiz Maker (CVE-2025-10042), demonstrating time-based blind SQLi via crafted HTTP headers. The PoC includes data extraction logic for admin credentials and hashes.
Description
The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an authorization bypass via reverse DNS (PTR record) spoofing on the 'checkWithoutToken' function in all versions up to, and including, 6.71. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated. Note: This is only exploitable on sites with an invalid API key.
Exploits (2)
The repository contains a functional SQL injection exploit for WordPress Quiz Maker (CVE-2025-10042), demonstrating time-based blind SQLi via crafted HTTP headers. The PoC includes data extraction logic for admin credentials and hashes.
The repository lacks actual exploit code and instead redirects users to an external download link (tinyurl.com). The README provides minimal technical details and reads like a sales pitch rather than a legitimate technical analysis.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H