Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-51556 | The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to arbitrary file uploads due to the plugin uploading and extracting .zip archives when scanning them for malware through the checkUploadedArchive() function in all versions up to, and including, 2.149. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 25 Feb 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cleantalk
Cleantalk security \& Malware Scan |
|
| CPEs | cpe:2.3:a:cleantalk:security_\&_malware_scan:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Cleantalk
Cleantalk security \& Malware Scan |
Wed, 12 Feb 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 12 Feb 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to arbitrary file uploads due to the plugin uploading and extracting .zip archives when scanning them for malware through the checkUploadedArchive() function in all versions up to, and including, 2.149. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. | |
| Title | Security & Malware scan by CleanTalk <= 2.149 - Unauthenticated Arbitrary File Upload | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-02-18T17:36:20.967Z
Reserved: 2025-01-13T18:54:59.767Z
Link: CVE-2024-13365
Updated: 2025-02-12T14:34:20.599Z
Status : Analyzed
Published: 2025-02-12T10:15:10.547
Modified: 2025-02-25T18:27:25.897
Link: CVE-2024-13365
No data.
OpenCVE Enrichment
No data.
EUVD