CVE-2026-1490
The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an authorization bypass via reverse DNS (PTR record) spoofing on the 'checkWithoutToken' function in all versions up to, and including, 6.71. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated. Note: This is only exploitable on sites with an invalid API key.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 1.16%
- CWE
- CWE-350
- Published
- 2026-02-15
- Last modified
- 2026-04-09
Affected products
- cleantalk Spam protection, Honeypot, Anti-Spam by CleanTalk
- cleantalk Spam protection, Honeypot, Anti-Spam by CleanTalk
Weakness type
Related vulnerabilities
- CVE-2026-55526 — PraisonAI: SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`)
- CVE-2026-56709 — Grav before 3.9.2 Host Header Injection via sendInvitationEmail
- CVE-2026-75514 — BunkerWeb: rDNS bypass via missing forward-confirmation (FCrDNS) in blacklist, greylist, and antibot
- CVE-2026-63118 — MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection
- CVE-2026-55391 — datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding
- CVE-2026-46611 — Glances: XML-RPC Server Missing Host Header Validation Enables DNS Rebinding Attack
- CVE-2026-12635 — Reliance on Reverse DNS Resolution for a Security-Critical Action in GitLab
- CVE-2026-42559 — RMCP: DNS rebinding vulnerability in rmcp Streamable HTTP server transport