Hackers Can Take Over 30,000 WordPress Sites Due to Critical CleanTalk Security Flaw (CVE-2024-13365) - #CVE-2024-13365
A critical vulnerability (CVE-2024-13365) with a CVSS score of 9.8 has been discovered in the Security & Malware scan by CleanTalk plugin for WordPress, affecting over 30,000 websites. The flaw allows unauthenticated attackers to upload malicious files within ZIP archives, potentially leading to full site takeover. Wordfence, a WordPress security company, identified the issue in the plugin's checkUploadedArchive() function and awarded a $1,716.00 bounty to researcher Lucio Sá. CleanTalk has released version 2.150 to address the vulnerability, and website owners are strongly advised to update immediately to mitigate the risk of exploitation.