The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to arbitrary file uploads due to the plugin uploading and extracting .zip archives when scanning them for malware through the checkUploadedArchive() function in all versions up to, and including, 2.149. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-51556 The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to arbitrary file uploads due to the plugin uploading and extracting .zip archives when scanning them for malware through the checkUploadedArchive() function in all versions up to, and including, 2.149. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sat, 12 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00694}

epss

{'score': 0.00685}


Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00653}

epss

{'score': 0.00694}


Tue, 25 Feb 2025 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Cleantalk
Cleantalk security \& Malware Scan
CPEs cpe:2.3:a:cleantalk:security_\&_malware_scan:*:*:*:*:*:wordpress:*:*
Vendors & Products Cleantalk
Cleantalk security \& Malware Scan

Wed, 12 Feb 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 12 Feb 2025 09:30:00 +0000

Type Values Removed Values Added
Description The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to arbitrary file uploads due to the plugin uploading and extracting .zip archives when scanning them for malware through the checkUploadedArchive() function in all versions up to, and including, 2.149. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
Title Security & Malware scan by CleanTalk <= 2.149 - Unauthenticated Arbitrary File Upload
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2025-02-18T17:36:20.967Z

Reserved: 2025-01-13T18:54:59.767Z

Link: CVE-2024-13365

cve-icon Vulnrichment

Updated: 2025-02-12T14:34:20.599Z

cve-icon NVD

Status : Analyzed

Published: 2025-02-12T10:15:10.547

Modified: 2025-02-25T18:27:25.897

Link: CVE-2024-13365

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.