200k Sites Exposed: Critical CleanTalk Flaw (CVSS 9.8) Allows RCE
ID: 6e6c8714-6e73-51ac-90ff-7ea24695c4ce
STIX ID: report--6e6c8714-6e73-51ac-90ff-7ea24695c4ce
Feed Name: securityonline.info
Threat Score
A critical authorization-bypass vulnerability (CVE-2026-1490, CVSS 9.8) in the CleanTalk WordPress anti-spam plugin allows attackers to spoof reverse DNS (PTR) records to bypass checks in the checkWithoutToken function and install/activate arbitrary plugins, potentially leading to remote code execution; only sites with invalid API keys are vulnerable and CleanTalk has released a patch in version 6.72—administrators should update immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
