CVE-2023-5239

The Security & Malware scan by CleanTalk WordPress plugin before 2.121 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. This may be used to bypass bruteforce protection.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cleantalk:security_\&_malware_scan:*:*:*:*:*:wordpress:*:*

History

21 Nov 2024, 08:41

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/1d748f91-773b-49d6-8f68-a27d397713c3 - Exploit, Third Party Advisory () https://wpscan.com/vulnerability/1d748f91-773b-49d6-8f68-a27d397713c3 - Exploit, Third Party Advisory

01 Dec 2023, 19:22

Type Values Removed Values Added
CPE cpe:2.3:a:cleantalk:security_\&_malware_scan:*:*:*:*:*:wordpress:*:*
CWE NVD-CWE-noinfo
First Time Cleantalk
Cleantalk security \& Malware Scan
References () https://wpscan.com/vulnerability/1d748f91-773b-49d6-8f68-a27d397713c3 - () https://wpscan.com/vulnerability/1d748f91-773b-49d6-8f68-a27d397713c3 - Exploit, Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

27 Nov 2023, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-11-27 17:15

Updated : 2024-11-21 08:41


NVD link : CVE-2023-5239

Mitre link : CVE-2023-5239

CVE.ORG link : CVE-2023-5239


JSON object : View

Products Affected

cleantalk

  • security_\&_malware_scan