CVE-2023-5239: Security & Malware scan by CleanTalk < 2.121 - IP Spoofing
The Security & Malware scan by CleanTalk WordPress plugin before 2.121 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. This may be used to bypass bruteforce protection.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-5239?
CVE-2023-5239 is a vulnerability found in the Security & Malware scan by CleanTalk WordPress plugin before version 2.121.
What is the severity of CVE-2023-5239?
CVE-2023-5239 has a severity rating of 7.5 (high).
How does CVE-2023-5239 affect CleanTalk Security & Malware Scan plugin?
CVE-2023-5239 allows an attacker to manipulate the client IP addresses retrieved from potentially untrusted headers, which can be used to bypass brute force protection.
What is the recommended solution for CVE-2023-5239?
To fix CVE-2023-5239, update the Security & Malware scan by CleanTalk plugin to version 2.121 or higher.
Where can I find more information about CVE-2023-5239?
You can find more information about CVE-2023-5239 at the following link: [CVE-2023-5239](https://wpscan.com/vulnerability/1d748f91-773b-49d6-8f68-a27d397713c3)