Vulnerability in a popular WordPress plug: spam protection can lead to illegal action

Article image Vulnerability in a popular WordPress plug: spam protection can lead to illegal action
Article image Vulnerability in a popular WordPress plug: spam protection can lead to illegal action
Publication date:01.10.2025
Blog category: Web Security

Renovated, it has been found that WordPress, which is used in more than 200,000 websites to protect against spam, has a vulnerability that allows the attackers to install additional plugins without the administrator permission. This vulnerability was estimated at 9.8 points out of 10 possible, which reflects its high degree of seriousness.

"A HIGHLY RATED ATI-SPAM FIREWALL WITH OVER 200,000 Installations Was Found to Have An Authentication Bypass Vulneracy that Enables Attackers to Gain Full Access Toving ASEBSITES WITH Flaw Lets Attackers Upload and Install Any Plugin, Including Malware, Granting Them Full Control of the Site. "

The vulnerability was found in the SPAM Protection, Anti-Spaam, Firewall by Cleantalk. It reveals a problem with authentication check that allows the attackers to get full access to websites without entering a user or password. This disadvantage allows the attackers to install any plugins, including harmful software, giving them full control of the site 🚀.

  • 📌 Much vulnerability in the popular WordPress plug is revealed.
  • 📌 Vulnerability allows the attackers to install additional plugins without the permission of the administrator.
  • 📌 Detecting and eliminating this kind of vulnerability is critical for the safety of the website.

FAQ

Which plugin was armed?

The vulnerability in the SPAM Protection, Anti-Spaam, Firewall by Cleantalk was revealed.

How do attackers use this vulnerability?

The attackers can access the website, including the ability to install additional plugins without entering a user or password.

How can this problem be solved?

It is recommended to update the plugin to version 6.44 or above.

🧩 Summary: A great vulnerability is found in a popular WordPress plug, which is used to protect against spam on more than 200,000 websites. Vulnerability allows the attackers to install additional plugins without the permission of the administrator. The detection and elimination of this kind of vulnerability is critical to ensure the safety of the website.
🧠 Own considerations: Since we live in a digital era, web-safety is becoming more important. Website administrators should regularly check their plugins for vulnerability, as attackers are constantly looking for new ways to gain unauthorized access. It is important not only to know about these vulnerability, but also to understand how to eliminate them. Website security is a constant process that requires regular monitoring, updating and elimination of vulnerability.

Comments

CSSnLaughs Avatar
Круто, що захист від спаму тепер став хакерським "шаржем"! Залишилося лише навчитись додавати смайлики до кодів замість витрачати час на їх усунення. А якщо серйозно, то це серйозний дзвіночок для всіх, хто любить залишати плагіни на автопілоті.
01.10.2025 09:00 CSSnLaughs