Latest Daily News Hosting, Technology News, Updates, and Trends
Latest Daily News Hosting, Technology News, Updates, and Trends
  • Home
  • News Categories
    • Cyber Security
    • Cloud Hosting
    • Data Center
    • WordPress
    • Search Engine Ranking
    • cPanel Hosting
    • CDN Hosting
    • Press Release
    • WordPress.org-Wp Engine Battle
    • World
  • Web Stories
 200K WordPress Websites Vulnerable to Cyberattacks 
Cyber Security WordPress

200K WordPress Websites Vulnerable to Cyberattacks 

by Manvinder Singh November 29, 2024 0 Comment

Vulnerabilities identified in Anti-spam, Firewall by CleanTalk Plugin for WordPress. It has exposed many WordPress sites to unauthenticated cyber attackers to install malware. 

In the latest WordPress news, Two critical vulnerabilities in WordPress’s Anti-spam plugin have affected the WordPress site. This Anti-Spam by clean talk was installed in over 200,000 Sites. These two flaws have exposed sites to cyberattacks. 

This Anti-spam firewall vulnerabilities allows the attackers to have full control of the website without providing any username and password. It lets the attackers install any plugin, including malware. 

Vulnerabilities Summary by Wordfence Intelligence 

These two vulnerabilities are identified as CVE-2024-10542 and CVE-2024-10781. 

CVE-2024-10542 

The Spam protection, Anti-Spam, Firewall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an authorization bypass via reverse DNS spoofing on the checkWithoutToken function in all versions up to, and including, 6.43.2.  

Impact 

This makes it possible for unauthenticated attackers to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated.  

Image Source: https://www.wordfence.com/blog/2024/11/200000-wordpress-sites-affected-by-unauthenticated-critical-vulnerabilities-in-anti-spam-by-cleantalk-wordpress-plugin/  

CVE-2024-10781 

The Spam protection, Anti-Spam, Firewall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to a missing empty value check on the ‘api_key’ value in the ‘perform’ function in all versions up to, and including, 6.44.  

Impact 

This makes it possible for unauthenticated attackers to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated. 

Image Source: https://www.wordfence.com/blog/2024/11/200000-wordpress-sites-affected-by-unauthenticated-critical-vulnerabilities-in-anti-spam-by-cleantalk-wordpress-plugin/  

The Screenshot of Vulnerability (CVE-2024-10542) Severity Rating 

Image Source: https://www.searchenginejournal.com/wordpress-anti-spam-plugin-vulnerability-hits-200k-sites/533844/ 

When were the vulnerabilities identified?  

30th October 2024 

Wordfence received the submission for the Authorization Bypass vis reverse DNS spoofing vulnerability (CVE-2024-10542) in Anti-spam by CleanTalk on 30th October 2024 through the Wordfence Bug Bounty Program.  

On the same day, Wordfence validated the report and confirmed the exploit. Wordfence users received a firewall rule to provide protection against any exploits that may target the first vulnerability.  

They sent full details of the vulnerability to the vendor and the vendor after acknowledging the report, started working on a fix. 

1st November 2024 

The partially patched version, 6.44, of the plugin was released. 

4th November 2024 

The Wordfence threat intelligence team identified an Authorization bypass due to Missing entry check vulnerability (CVE-2024-10781) during patch review. 

Again, Wordfence users received a firewall rule to provide protection against any exploits that may target the second vulnerability. 

14th November 2024 

The fully patched version, 6.45, was released. 

29th November 2024 

Users receive the same protection against the Authorization Bypass via Reverse DNS Spoofing vulnerability (CVE-2024-10542). 

4th December 2024 

Users will receive the same protection against the Authorization Bypass due to Missing entry check vulnerability (CVE-2024-10781). 
 

Tags: Latest Cybersecurity News Latest WordPress News Vulnerable WordPress Websites Website Security News
Previous post
Next post

Manvinder Singh (Website)

author

Manvinder Singh, with 15 years in the web hosting industry, now shares his expertise as a news auditor, enriching web hosting users with valuable insights and guidance. His extensive experience spans server management, security protocols, and customer support, making him a trusted source in navigating the complexities of web hosting solutions. Passionate about transparency and reliability, Manvinder continues to empower businesses and individuals with practical knowledge, ensuring they make informed decisions in optimizing their online presence.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recent News

  • CITRA to Sign Lease Contract with Google to Establish Three Data Centers  
  • Last Algorithm Update of 2024; Google Rolls Out December Core Update
  • WP Engine Scores Legal Win Against Automattic
  • Search Engine Update: Google Resolved Indexing Issues
  • Google Asks US Government to Break Up Microsoft’s Cloud Deal with Open AI

Recent Comments

No comments to show.

Archives

  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • October 2022
  • September 2022
  • August 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021

Categories

  • Cloud Hosting
  • cPanel Hosting
  • Cyber Security
  • Data Center
  • Press Release
  • Search Engine Ranking
  • WordPress
  • WordPress.org-Wp Engine Battle
  • World

About Hosting Daily News

Hosting Daily news primarily focuses on delivering quality and authentic content related to the hosting industry. Hosting Daily News covers a wide range of news, articles, announcements, community-based content to keep the tech enthusiasts engaged with the latest development of hosting industry which includes Cloud Hosting, Web Hosting, cybersecurity, WordPress, AI technology and various topics related to hosting. We aim to foster collaborations and knowledge sharing content among industry stakeholders.

Top Categories

  • Cloud Hosting
  • cPanel Hosting
  • Cyber Security
  • Data Center
  • Press Release
  • Search Engine Ranking
  • WordPress
  • WordPress.org-Wp Engine Battle
  • World

Latest News

  • CITRA to Sign Lease Contract with Google to Establish Three Data Centers  
  • Last Algorithm Update of 2024; Google Rolls Out December Core Update
  • WP Engine Scores Legal Win Against Automattic
  • Search Engine Update: Google Resolved Indexing Issues
  • Google Asks US Government to Break Up Microsoft’s Cloud Deal with Open AI
Copyright © 2025 HostingDailyNews. All Right Reserved.
  • Instagram
  • Facebook
  • X
  • LinkedIn