The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to arbitrary file uploads due to the plugin uploading and extracting .zip archives when scanning them for malware through the checkUploadedArchive() function in all versions up to, and including, 2.149. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
Metrics
Affected Vendors & Products
References
History
Tue, 25 Feb 2025 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Cleantalk
Cleantalk security \& Malware Scan |
|
CPEs | cpe:2.3:a:cleantalk:security_\&_malware_scan:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Cleantalk
Cleantalk security \& Malware Scan |
Wed, 12 Feb 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 12 Feb 2025 09:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to arbitrary file uploads due to the plugin uploading and extracting .zip archives when scanning them for malware through the checkUploadedArchive() function in all versions up to, and including, 2.149. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. | |
Title | Security & Malware scan by CleanTalk <= 2.149 - Unauthenticated Arbitrary File Upload | |
Weaknesses | CWE-434 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-02-18T17:36:20.967Z
Reserved: 2025-01-13T18:54:59.767Z
Link: CVE-2024-13365

Updated: 2025-02-12T14:34:20.599Z

Status : Analyzed
Published: 2025-02-12T10:15:10.547
Modified: 2025-02-25T18:27:25.897
Link: CVE-2024-13365

No data.