[WordPress Security] 200,000 WordPress Sites Affected by Unauthenticated Critical Vulnerabilities in Anti-Spam by CleanTalk WordPress Plugin


We urge users to update their sites with the latest patched version of this plugin as soon as possible.
Wordfence-Logo.png (email.wordfence.com/e3t/Ctc/GC+113/cwG7R04/VVTKcZ2yMTDcVYzJ7s8w2GGWW1HN78y5nR7RkN1xVmZs3prCCW7lCdLW6lZ3pxW2Zpt4Z4NFfNSN3j3GHD6StkLW4cQsD34n6wMYVnPRQf5NnMXwW3WWSlD152dgJW7S61xs3kVYhNW2zsT6_6906CwN6w… )
FeaturedImage_Wordfence_160.03.02 (email.wordfence.com/e3t/Ctc/GC+113/cwG7R04/VVTKcZ2yMTDcVYzJ7s8w2GGWW1HN78y5nR7RkN1xVmZs5m_5PW7lCGcx6lZ3k-N7qCrD1mktg_W8Jf8xC2YqrpMW6Jt0dx8CNwmZW1dcW4y4FFvjHW2Kg9wC7chLjZW4NkC-Q4TjjM6W5P4lcB3kgC3TW6… )
On October 30th, 2024, we received a submission for an Authorization Bypass via Reverse DNS Spoofing vulnerability in Anti-Spam by CleanTalk, a WordPress plugin with more than 200,000 active installations (email.wordfence.com/e3t/Ctc/GC+113/cwG7R04/VVTKcZ2yMTDcVYzJ7s8w2GGWW1HN78y5nR7RkN1xVmZs5m_5PW7lCGcx6lZ3k-N7qCrD1mktg_W8Jf8xC2YqrpMW6Jt0dx8CNwmZW1dcW4y4FFvjHW2Kg9wC7chLjZW4NkC-Q4TjjM6W5P4lcB3kgC3TW6… ) . This vulnerability makes it possible for an unauthenticated attacker to install and activate arbitrary plugins on a vulnerable site, which can be leveraged to achieve remote code execution. A few days later on November 4th, our Threat Intelligence Team discovered another vulnerability in the same functionality that could be leveraged to perform the same actions.
Read The Full Post Here (email.wordfence.com/e3t/Ctc/GC+113/cwG7R04/VVTKcZ2yMTDcVYzJ7s8w2GGWW1HN78y5nR7RkN1xVmZs5m_5PW7lCGcx6lZ3k-N7qCrD1mktg_W8Jf8xC2YqrpMW6Jt0dx8CNwmZW1dcW4y4FFvjHW2Kg9wC7chLjZW4NkC-Q4TjjM6W5P4lcB3kgC3TW6… )
Props to mikemyers (email.wordfence.com/e3t/Ctc/GC+113/cwG7R04/VVTKcZ2yMTDcVYzJ7s8w2GGWW1HN78y5nR7RkN1xVmYg5m_5PW50kH_H6lZ3lYW5slS596HT9QXW7NYGKq5NTTpGW8yzqWg9hS379W63Tdl-4rXRWNW4yRLfR4y69TRW4CSfDK8VVJ3NW1PjqLZ8dSlM-W… ) who discovered and responsibly reported this vulnerability through the Wordfence Bug Bounty Program (email.wordfence.com/e3t/Ctc/GC+113/cwG7R04/VVTKcZ2yMTDcVYzJ7s8w2GGWW1HN78y5nR7RkN1xVmZM3prCCW7Y8-PT6lZ3lrW8wS41F7pL4qFW4Xlxnw60rjhjW6nXsTG5FHZ0kV1jsqy17kW3yW5vRL73264WkPW7RpYDk2W-pPSW5bv0ds5FlLvJW9… ) . This researcher earned a bounty of $4,095.00 for this discovery. Our mission is to Secure the Web, which is why we are investing in quality vulnerability research and collaborating with researchers of this caliber through our Bug Bounty Program. We are committed to making the WordPress ecosystem more secure, which ultimately makes the entire web more secure.
Wordfence Premium (email.wordfence.com/e3t/Ctc/GC+113/cwG7R04/VVTKcZ2yMTDcVYzJ7s8w2GGWW1HN78y5nR7RkN1xVm-23prCCW8wLKSR6lZ3nlN3hs_CJsJXvzN8HsStk_9dRzW7wGmTB2f1Wn4W7B__Bp33GPxtW2M2wQv6CSphfW3x8Nx04YwGYbW91lhcF64BhF_W6G… ) , Wordfence Care (email.wordfence.com/e3t/Ctc/GC+113/cwG7R04/VVTKcZ2yMTDcVYzJ7s8w2GGWW1HN78y5nR7RkN1xVmZM3prCCW7Y8-PT6lZ3p8W3R1pDX26dyYKW2bF2Zm7y11hgW7hsvk-6LQ3LnN1MZ2kMjZlYMW7KRGlH4vj_wHV3kQNW39s3CqW3Hsw213wY7hJW6x… ) , and Wordfence Response (email.wordfence.com/e3t/Ctc/GC+113/cwG7R04/VVTKcZ2yMTDcVYzJ7s8w2GGWW1HN78y5nR7RkN1xVm-23prCCW8wLKSR6lZ3nqW6kV-867fRWMdW8X7qLF4z57MLW7cRttP15rrmhW2B3KtV7-2-89W6YFt0r6ptYPqW6F8BvL3tRKgPW7sgL974gPh2fN… ) users received a firewall rule to protect against any exploits targeting the first vulnerability, Authorization Bypass via Reverse DNS Spoofing, on October 30, 2024. Sites using the free version of Wordfence will receive the same protection 30 days later on November 29, 2024.
Wordfence Premium (email.wordfence.com/e3t/Ctc/GC+113/cwG7R04/VVTKcZ2yMTDcVYzJ7s8w2GGWW1HN78y5nR7RkN1xVm-23prCCW8wLKSR6lZ3nlN3hs_CJsJXvzN8HsStk_9dRzW7wGmTB2f1Wn4W7B__Bp33GPxtW2M2wQv6CSphfW3x8Nx04YwGYbW91lhcF64BhF_W6G… ) , Wordfence Care (email.wordfence.com/e3t/Ctc/GC+113/cwG7R04/VVTKcZ2yMTDcVYzJ7s8w2GGWW1HN78y5nR7RkN1xVmZM3prCCW7Y8-PT6lZ3p8W3R1pDX26dyYKW2bF2Zm7y11hgW7hsvk-6LQ3LnN1MZ2kMjZlYMW7KRGlH4vj_wHV3kQNW39s3CqW3Hsw213wY7hJW6x… ) , and Wordfence Response (email.wordfence.com/e3t/Ctc/GC+113/cwG7R04/VVTKcZ2yMTDcVYzJ7s8w2GGWW1HN78y5nR7RkN1xVm-23prCCW8wLKSR6lZ3nqW6kV-867fRWMdW8X7qLF4z57MLW7cRttP15rrmhW2B3KtV7-2-89W6YFt0r6ptYPqW6F8BvL3tRKgPW7sgL974gPh2fN… ) users received a firewall rule to protect against any exploits targeting the second vulnerability, Authorization Bypass due to Missing Empty Value Check, on November 4, 2024. Sites using the free version of Wordfence will receive the same protection 30 days later on December 4, 2024.
We urge users to update their sites with the latest patched version of Anti-Spam by CleanTalk, version 6.45 at the time of this writing, as soon as possible.
READ THE FULL POST HERE (email.wordfence.com/e3t/Ctc/GC+113/cwG7R04/VVTKcZ2yMTDcVYzJ7s8w2GGWW1HN78y5nR7RkN1xVmZs5m_5PW7lCGcx6lZ3k-N7qCrD1mktg_W8Jf8xC2YqrpMW6Jt0dx8CNwmZW1dcW4y4FFvjHW2Kg9wC7chLjZW4NkC-Q4TjjM6W5P4lcB3kgC3TW6… )
📣 Did you know Wordfence runs a Bug Bounty Program (email.wordfence.com/e3t/Ctc/GC+113/cwG7R04/VVTKcZ2yMTDcVYzJ7s8w2GGWW1HN78y5nR7RkN1xVmZM3prCCW7Y8-PT6lZ3lrW8wS41F7pL4qFW4Xlxnw60rjhjW6nXsTG5FHZ0kV1jsqy17kW3yW5vRL73264WkPW7RpYDk2W-pPSW5bv0ds5FlLvJW9… ) for all WordPress plugins and themes at no cost to vendors? This month we’re celebrating the End of Year Holiday Extravaganza and the WordPress Superhero Challenge! Through December 9th, 2024:
– All in-scope vulnerability types for WordPress plugins/themes with >= 1,000 active installations are in-scope for ALL researchers – All plugins and themes with 50-999 active installs hosted in the WordPress.org repository and updated within the last 2 years are in-scope for all researchers! – Minimum bounty of $5 for all valid in-scope submissions. – All researchers earn automatic bonuses of between 5% to 180% for valid submissions – Pending report limits are increased for all – It’s possible to earn up to $31,200 for high impact vulnerabilities! – Get started today! (email.wordfence.com/e3t/Ctc/GC+113/cwG7R04/VVTKcZ2yMTDcVYzJ7s8w2GGWW1HN78y5nR7RkN1xVmZM3prCCW7Y8-PT6lZ3lrW8wS41F7pL4qFW4Xlxnw60rjhjW6nXsTG5FHZ0kV1jsqy17kW3yW5vRL73264WkPW7RpYDk2W-pPSW5bv0ds5FlLvJW9… )
The Full Product Lineup
wf-stacked-free-1 (email.wordfence.com/e3t/Ctc/GC+113/cwG7R04/VVTKcZ2yMTDcVYzJ7s8w2GGWW1HN78y5nR7RkN1xVmZM3prCCW7Y8-PT6lZ3pTVlSZRp1Mz34mW2-RGGv6GQsWDW776B_m3wNWx5W4YWG1s5rv7KGN1Vq_qzl2ctWN3H5XJW3cmGxV6qt368s0s9FW53Tr… )
wf-stacked-premium-1 (email.wordfence.com/e3t/Ctc/GC+113/cwG7R04/VVTKcZ2yMTDcVYzJ7s8w2GGWW1HN78y5nR7RkN1xVm-23prCCW8wLKSR6lZ3m3VQ8JxL4rmhBsVnD0Ry6ZbHBwW90QHgZ4m9JnNN863PVF7lTzTW7KvydL5lwCFtW8lWRhG3LJbr2V7_Wn255NjBWV7W0L… )
wf-stacked-care-3 (email.wordfence.com/e3t/Ctc/GC+113/cwG7R04/VVTKcZ2yMTDcVYzJ7s8w2GGWW1HN78y5nR7RkN1xVmZM3prCCW7Y8-PT6lZ3pwW3HPKlW5bPyZ5W3c8B3w2ndbDlW2H93BV2KNnynW56TGtW3Hhd5bVThw0w5btntpW87lwVT9dWwfLW6SGRTs9cXnTTW8… )
wf-stacked-response-2 (email.wordfence.com/e3t/Ctc/GC+113/cwG7R04/VVTKcZ2yMTDcVYzJ7s8w2GGWW1HN78y5nR7RkN1xVm-23prCCW8wLKSR6lZ3nqW6kV-867fRWMdW8X7qLF4z57MLW7cRttP15rrmhW2B3KtV7-2-89W6YFt0r6ptYPqW6F8BvL3tRKgPW7sgL974gPh2fN… )
Wordfence CLI (email.wordfence.com/e3t/Ctc/GC+113/cwG7R04/VVTKcZ2yMTDcVYzJ7s8w2GGWW1HN78y5nR7RkN1xVmZM3prCCW7Y8-PT6lZ3nzW4xnQYJ3cLZR7W5Drj7S3Q03rsW8MywQ478D40KVgGF612Y1CqMW5frxXd3L7_46W96xZD71r9XLnW43zmcB3tGhTNN3… )
Wordfence Intelligence (email.wordfence.com/e3t/Ctc/GC+113/cwG7R04/VVTKcZ2yMTDcVYzJ7s8w2GGWW1HN78y5nR7RkN1xVmZM3prCCW7Y8-PT6lZ3nZW6n–h82pSmVDW8NMNn33rMTMHW66z5H05y_54YW2TTCds8ZwpjkW6Z1Zf74_NK1yW5Bn_J51mmDxdV1bCnK7zHrZ-W8… )
logo-defiant (email.wordfence.com/e3t/Ctc/GC+113/cwG7R04/VVTKcZ2yMTDcVYzJ7s8w2GGWW1HN78y5nR7RkN1xVmZs3prCCW7lCdLW6lZ3nCW5flSV61X2DfNW7_Dbj87GPMJxW3B6zlH6dK118V1XGBd4l4PZZN3JyPHl8lMPKN3kCStwpQmb_N7DmvDHlGJwgW5FSz… )
Defiant, Inc., 1700 Westlake Ave N STE 200
Seattle, WA 98109 United States
Unsubscribe (email.wordfence.com/hs/preferences-center/en/direct?data=W2nXS-N30h-H1W2RtnYC2CN5N3W1VgY-L32zmrrW30Fl0m47Fz6_W2qXKC43F9DXDW219CL13LGzHcW4kf3FV4tvs6FW4krvGc4pkc2mW1Xc3qk3g2yD0W3FgcbZ3CdhgMW1Lrglg36n… ) Manage Preferences (email.wordfence.com/hs/preferences-center/en/page?data=W2nXS-N30h-H1W2RtnYC2CN5N3W1VgY-L32zmrrW30Fl0m47Fz6_W2qXKC43F9DXDW219CL13LGzHcW4kf3FV4tvs6FW4krvGc4pkc2mW1Xc3qk3g2yD0W3FgcbZ3CdhgMW1Lrglg36nmj… )
ISO_27001 (email.wordfence.com/e3t/Ctc/GC+113/cwG7R04/VVTKcZ2yMTDcVYzJ7s8w2GGWW1HN78y5nR7RkN1xVmZs3prCCW7lCdLW6lZ3nCW2r_l17579JXYW7dx-GG8XFVZFW21lMGD3Xj4ZlW8R5j_43c_1sqN4lh68zjWrg1M63bvsq6qQmW6Psv5f4DJBGBW2-y… )
You’re receiving this email because you signed up to the Wordfence WordPress security mailing list.

コメントを残す

メールアドレスが公開されることはありません。 が付いている欄は必須項目です

CAPTCHA