Логотип exploitDog
bind:CVE-2024-10781
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-10781

Количество 3

Количество 3

nvd логотип

CVE-2024-10781

около 1 года назад

The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an missing empty value check on the 'api_key' value in the 'perform' function in all versions up to, and including, 6.44. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-m52x-q4c4-72qw

около 1 года назад

The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an missing empty value check on the 'api_key' value in the 'perform' function in all versions up to, and including, 6.44. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated.

CVSS3: 8.1
EPSS: Низкий
fstec логотип

BDU:2024-10548

больше 1 года назад

Уязвимость модулей защиты от спама Spam protection, AntiSpam, FireWall плагина CleanTalk для системы управления содержимым сайта WordPress, связанная с некорректной обработкой исключительных состояний, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-10781

The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an missing empty value check on the 'api_key' value in the 'perform' function in all versions up to, and including, 6.44. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated.

CVSS3: 8.1
5%
Низкий
около 1 года назад
github логотип
GHSA-m52x-q4c4-72qw

The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an missing empty value check on the 'api_key' value in the 'perform' function in all versions up to, and including, 6.44. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated.

CVSS3: 8.1
5%
Низкий
около 1 года назад
fstec логотип
BDU:2024-10548

Уязвимость модулей защиты от спама Spam protection, AntiSpam, FireWall плагина CleanTalk для системы управления содержимым сайта WordPress, связанная с некорректной обработкой исключительных состояний, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.1
5%
Низкий
больше 1 года назад

Уязвимостей на страницу