Unauthorized User Interaction in CleanTalk Plugin for WordPress
CVE-2020-36698
8.8HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 20 October 2023
What is CVE-2020-36698?
The CleanTalk Security & Malware Scan plugin for WordPress is susceptible to unauthorized user interaction, affecting versions up to 2.50. This vulnerability arises from inadequate capability checks on several AJAX actions, along with nonce disclosure visible in the administrative dashboard's source code. This enables authenticated users, including those with subscriber-level permissions, to exploit the vulnerability to invoke functions, potentially leading to file deletions and unauthorized file uploads.
Affected Version(s)
Login Security, FireWall, Malware removal by CleanTalk 0 <= 2.50