CVE-2024-10570: Security & Malware scan by CleanTalk <= 2.145 - Authorization Bypass via Reverse DNS Spoofing to Unauthenticated SQL Injection
The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to unauthorized SQL Injection due to an authorization bypass via reverse DNS spoofing on the checkWithoutToken function in all versions up to, and including, 2.145, as well as insufficient input sanitization and validation. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10570?
CVE-2024-10570 has a high severity rating due to the potential for unauthorized SQL Injection.
How do I fix CVE-2024-10570?
To fix CVE-2024-10570, update the CleanTalk Security & Malware scan plugin to version 2.146 or later.
What versions are affected by CVE-2024-10570?
CVE-2024-10570 affects all versions of the CleanTalk Security & Malware scan plugin up to and including 2.145.
What does CVE-2024-10570 exploit?
CVE-2024-10570 exploits an authorization bypass via reverse DNS spoofing affecting the checkWithoutToken function.
What are the consequences of CVE-2024-10570?
The consequences of CVE-2024-10570 include potential unauthorized access to the database through SQL Injection.