
CleanTalk WordPress Plugin Vulnerability Threatens Up To 200K Sites via @sejournal, @martinibuster
- ●A critical vulnerability rated 9.8/10 was found in the CleanTalk Antispam WordPress plugin, allowing unauthenticated attackers to install vulnerable plugins for remote code execution.
- ●The flaw arises from improper identity verification in the 'checkWithoutToken' function, enabling attackers to exploit the plugin without a valid API key.
- ●Users are advised to update to the latest version of the CleanTalk plugin (6.72) to mitigate security risks.




