logo

CleanTalk Plugin for WordPress Exposes Sites to Authorization Bypass via Reverse DNS

ID: d1c5854a-c5e7-5353-8250-851816fd4286

STIX ID: report--d1c5854a-c5e7-5353-8250-851816fd4286

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-02-16

Date Updated: 2026-04-22

Author: Divya

...
...

**Executive Summary:** A critical CVE-2026-1490 vulnerability in the CleanTalk WordPress plugin allows unauthenticated attackers to bypass authorization via PTR record spoofing and install arbitrary plugins (potential RCE); administrators should update to version 6.72 immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.