A critical vulnerability in the CleanTalk Spam Protection plugin for WordPress lets attackers bypass authorization and seize control of sites.
Tracked as CVE-2026-1490, this flaw affects thousands of WordPress installations using the plugin for spam filtering.
With a CVSS score of 9.8, it poses an urgent risk, enabling unauthenticated attackers to install arbitrary plugins and potentially execute remote code.
The problem lies in the plugin’s checkWithoutToken function. This routine verifies requests by relying on Reverse DNS (PTR) records instead of secure methods like cryptographic tokens.
Attackers exploit this by spoofing PTR records to mimic requests from CleanTalk’s trusted servers. No authentication token is needed, making the attack straightforward.
| CVE ID | CVSS Score | Description |
|---|---|---|
| CVE-2026-1490 | 9.8 (Critical) | Authorization Bypass via Reverse DNS (PTR record) Spoofing in CleanTalk Spam Protection leads to unauthenticated arbitrary plugin installation and potential RCE. |
Once exploited, attackers gain full admin-like powers. They can install any plugin from the WordPress repository, including those with known flaws or backdoors.
This opens doors to remote code execution (RCE), file modifications, database theft, and persistent access. For example, a malicious plugin could upload webshells or exfiltrate user data.
Exploitation requires a key condition: the CleanTalk plugin must be active on a WordPress site with an invalid or missing API key.
This hits development environments, lapsed subscriptions, or abandoned sites hard scenarios where plugins linger without renewal. Attack complexity is low, with no user interaction needed, amplifying the threat.
Security researcher Nguyen Ngoc Duc (duc193) uncovered the issue and disclosed it on February 14, 2026.
CleanTalk fixed it in version 6.72 by strengthening verification beyond PTR records. WordPress admins should check their plugin version immediately and update.
Sites with invalid API keys face the highest risk deactivate the plugin or renew keys if patching isn’t feasible.
This flaw underscores a key lesson: never trust DNS alone for authorization. WordPress users should audit plugins regularly, enable auto-updates, and monitor for invalid API states. As attackers scan for easy wins, swift action prevents takeover.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google