CVE-2026-1490Disclosure

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an authorization bypass via reverse DNS (PTR record) spoofing on the 'checkWithoutToken' function in all versions up to, and including, 6.71. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated. Note: This is only exploitable on sites with an invalid API key.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-350

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 18 mentions across 7 observed days
  • Momentum state: declining

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 16 signals
  • Disclosure: 9 classified signals
  • General: 2 classified signals
  • Peaked 6d ago at 6 mentions (2026-02-15); latest day: 1
  • 18 total mentions across 7 days

Deep dive

Activity timeline18 mentions / 7d
02356Mentions · 2026-02-15: 6Mentions · 2026-02-16: 5Mentions · 2026-02-17: 2Mentions · 2026-02-20: 2Mentions · 2026-02-24: 1Mentions · 2026-02-26: 1Mentions · 2026-04-03: 1PoC Mentioned / Linked · 2026-02-15: 1Patch / Workaround · 2026-02-15: 1Patch / Workaround · 2026-02-16: 3Patch / Workaround · 2026-02-20: 1Patch / Workaround · 2026-02-24: 1Patch / Workaround · 2026-02-26: 1Technical Details · 2026-02-15: 5Technical Details · 2026-02-16: 5Technical Details · 2026-02-17: 2Technical Details · 2026-02-20: 2Technical Details · 2026-02-24: 1Technical Details · 2026-02-26: 102-1502-1602-1702-2002-2402-2604-03
Signal classification3 categories
Disclosure
950.0%
Patch
738.9%
General
211.1%
Referenced assets15 URLs
Classification over time
DateTotalLabels
2026-02-156
Disclosure4General1Patch1
2026-02-165
Disclosure2Patch3
2026-02-172
Disclosure2
2026-02-202
Disclosure1Patch1
2026-02-241
Patch1
2026-02-261
Patch1
2026-04-031
General1
Full discourse18 posts
  • 情シスマン®【公式】USEN GATE 02@joshisuman_usen
    General

    #セキュラボ 【CleanTalk WordPress プラグインに重大な脆弱性(CVE-2026-1490)、20万サイトが攻撃リスクに】 CleanTalk WordPress プラグインに重大な脆弱性が発覚!詳細を分析してみた。 USEN ICT Solutionsが運営するサイバーセキュリティラボの新記事はこちら▼ https://www.gate02.ne.jp/lab/security-article/cleantalk-vulnerability-cve-2026-1490/?utm_medium=social&utm_source=tw&utm_campaign=cybersecuritylabo2026_0403_1040&utm_content=joshisuman_usen

    Post summary

    A tweet announces a serious CVE-2026-1490 flaw in the CleanTalk WordPress plugin, warning that up to 200,000 sites might be impacted, but offers no exploit details, PoC, or mitigation advice.

    010150416
    30.4K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    CleanTalk flaw CVE-2026-1490 (CVSS 9.8) exposes 200k sites to RCE via DNS spoofing. Attackers bypass auth to install plugins. Update to v6.72 now. #CleanTalk #WordPress #CyberSecurity #CVE20261490 #RCE #InfoSec #PatchNow https://securityonline.info/200k-sites-exposed-critical-cleantalk-flaw-cvss-9-8-allows-rce/

    Post summary

    CVE-2026-1490 is a critical RCE flaw in CleanTalk that allows DNS spoofing and authentication bypass, affecting roughly 200,000 WordPress sites. Users are advised to update to version 6.72 immediately.

    03055532
    10.3K followersView on X
  • Netlas.io@Netlas_io
    Disclosure

    CVE-2026-1490: Vulnerability in CleanTalk WordPress plugin, 9.8 rating 🔥 The vulnerability allows attackers to install any plugin on an affected website, which could be the first step in any attack chain. Search at http://Netlas.io: 👉 Link: https://nt.ls/wZ4Qu

    Post summary

    CVE-2026-1490 is a new vulnerability in the CleanTalk WordPress plugin that permits attackers to install arbitrary plugins, potentially enabling further attacks.

    14050539
    7.2K followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Disclosure

    A critical vulnerability (CVE-2026-1490, CVSS 9.8) in CleanTalk WordPress plugin up to version 6.71 risks 200,000 sites by allowing unauthenticated attackers to install plugins and execute remote code. #CleanTalk #WordPressRisk #Vietnam https://ift.tt/SejYUxq

    Post summary

    The post announces the discovery of CVE-2026-1490, a critical remote code execution flaw in CleanTalk WordPress plugin (versions ≤6.71) that can be exploited by unauthenticated attackers, potentially impacting ~200,000 sites.

    00011109
    3.6K followersView on X
  • iototsecnews@iototsecnews
    Patch

    WordPress CleanTalk プラグインの脆弱性 CVE-2026-1490 が FIX:Reverse DNS 偽装と RCE https://iototsecnews.jp/2026/02/16/cleantalk-plugin-for-wordpress-exposes-sites-to-authorization-bypass-via-reverse-dns/ 脆弱性 CVE-2026-1490 (CVSS 9.8) は、CleanTalk Spam Protection の checkWithoutToken 関数が Reverse DNS (PTR) 情報を信頼して認証を行う実装に起因します。本来は、暗号トークンやサーバ側検証で確認すべきところを、偽装可能な DNS レコードに依存していた点が問題でした。その結果として、未認証の攻撃者であっても認可を回避し、任意の WordPress プラグインをインストール/有効化できる状態となります。特に API key が無効な環境で成立しやすく、RCE につながる危険性があるため、バージョン 6.72 への更新が必要です。ご利用のチームは、ご注意ください。 #CleanTalkSpamProtectionplugin #CVE20261490 #Vulnerability #WordPress

    Post summary

    The article reports a high‑severity CVE‑2026‑1490 in CleanTalk’s WordPress plugin that allows reverse‑DNS spoofing to bypass authentication and potentially achieve RCE, and it recommends updating to version 6.72.

    01000153
    485 followersView on X
  • Alborz Safe@EthicalSafe
    Patch

    برای پلاگین CleanTalk مربوط به Wordpress ، آسیب پذیری با کد شناسایی CVE-2026-1490 و از نوع Authorization Bypass منتشر شده است که به هکرها امکان نصب سایر پلاگین های دیگر و در نهایت امکان RCE را می دهد . برای امن سازی ، این پلاگین را به روز رسانی نمایید. https://t.co/OxnuCfgyA5

    Post summary

    The tweet alerts about the newly disclosed CVE-2026-1490 Authorization Bypass in the CleanTalk WordPress plugin, explains it enables RCE, and urges users to update the plugin to mitigate the risk.

    0001054
    3 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-1490 Arbitrary Plugin Installation Vulnerability in CleanTalk WordPress Security Plugin https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1490

    Post summary

    The provided text references CVE‑2026‑1490 and its description but contains no additional detail or actionable information.

    0001049
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1490 The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an authorization bypass vi… https://www.cve.org/CVERecord?id=CVE-2026-1490

    Post summary

    CVE-2026-1490 exposes the CleanTalk WordPress plugin to an authorization bypass, enabling attackers to install arbitrary plugins without authorization.

    00010632
    56.4K followersView on X
  • Quttera - eCommerce Security@MNovofastovsky
    Patch

    Critical #WordPress plugin flaw (CVE-2026-1490) CleanTalk Anti-Spam (≤ 6.71) has an authorization bypass via reverse DNS (PTR) spoofing in its checkWithoutToken logic, letting unauthenticated attackers install/activate arbitrary plugins on sites with invalid API keys, which can lead to RCE if another vulnerable plugin is present. Score: 9.8 CRITICAL. https://nvd.nist.gov/vuln/detail/CVE-2026-1490 🔎 WordPress sites using CleanTalk must update/remove the plugin and ensure valid API keys — this isn’t just spam protection, it’s a full perimeter risk. 🛠 Run a malware & backdoor scan afterward → https://quttera.com/remove-malware-from-website #WordPress #CVE20261490 #WebSecurity #Infosec #WordPressSecurity #Malware #CVE

    Post summary

    A critical authorization bypass in CleanTalk Anti‑Spam (≤6.71) lets unauthenticated attackers install arbitrary plugins, potentially leading to RCE; users must update or remove the plugin and enforce valid API keys.

    0000045
    37 followersView on X
  • Patrick DUHAUT - ONI@oni_sas
    Patch

    Faille CleanTalk: une vulnérabilité RCE critique menace 200 000 sites WordPress Anti-spam qui ouvre la porte ? CleanTalk: faille critique (CVE-2026-1490). Jusqu’à 200k sites #WordPress exposés. MàJ 6.72+ immédiate. #Sécurité Détails et plan d’action : voir nos actus 👆 https://t.co/apcdbZ1uDv

    Post summary

    CleanTalk has announced a critical RCE vulnerability (CVE-2026-1490) affecting up to 200k WordPress sites and urges immediate update to version 6.72+.

    0000041
    16.3K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-1490 (CVSS:9.8, CRITICAL) is Awaiting Analysis. The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugi..https://nvd.nist.gov/vuln/detail/CVE-2026-1490 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    This tweet announces a new critical CVE (CVE-2026-1490) affecting CleanTalk’s WordPress plugin, indicating it is awaiting analysis, with no proof of exploitation or patch details disclosed.

    0000025
    171 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-1490 - Critical The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an authorization bypass via reverse DNS (PTR r... https://www.thehackerwire.com/vulnerability/CVE-2026-1490/ https://t.co/Ykoey09hHh

    Post summary

    The tweet announces a critical vulnerability in the CleanTalk WordPress plugin that permits arbitrary plugin installation via a reverse DNS authorization bypass, with no PoC or active exploitation evidence provided.

    0000062
    112 followersView on X
  • ThreatCluster@threatcluster
    Patch

    CVE-2026-1490: Critical CleanTalk plugin flaw enables authorization bypass on WordPress via reverse DNS, CVSS 9.8, affecting thousands of sites. Admins should review and patch. #WordPress https://threatcluster.io/cluster/critical-cleantalk-plugin-vulnerability-enables-authorizatio-db697714

    Post summary

    The text announces CVE-2026-1490, a high‑severity authorization bypass flaw in the CleanTalk WordPress plugin, and urges administrators to patch affected sites.

    0000043
    71 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Disclosure

    🚨 CRITICAL: CVE-2026-1490 allows unauthorized plugin installs in all versions of CleanTalk for WordPress. Remote attackers can exploit sites with invalid API keys. Audit ASAP! 🔍 https://radar.offseq.com/threat/cve-2026-1490-cwe-350-reliance-on-reverse-dns-reso-0fc3066a #OffSeq... https://t.co/v1eO5V667p

    Post summary

    The tweet announces CVE‑2026‑1490 as a critical flaw enabling unauthorized plugin installations on CleanTalk‑protected WordPress sites by bypassing API key validation, urging administrators to audit promptly.

    0000040
    265 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-1490: Spam protection, Honeypot, Anti-S... PTR record spoofing in CleanTalk turns anti-spam into your attack vector - trivial RCE for sites with invalid API keys v... https://zerodaysignal.com/vulnerability/CVE-2026-1490 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet discloses CVE-2026-1490, a PTR record spoofing vulnerability in CleanTalk that allows trivial remote code execution on sites with invalid API keys, and directs readers to a ZeroDaySignal page for more information.

    0000063
    131 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-1490 📊 Severity: 9.8 🚨 Risk Level: Critical 🧩 Affects: Wordpress Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-1490 #CVE-2026-1490 #CVE #Critical #Wordpress #CyberSecurity #InfoSec https://t.co/75E4eD7jcW

    Post summary

    The tweet announces CVE-2026-1490 as a critical WordPress vulnerability with a 9.8 severity score, but provides no PoC, exploit, or patch details.

    0000054
    56 followersView on X
  • Volerion@VolerionSec
    Patch

    🚨 CVE-2026-1490: CleanTalk Spam Protection plugin for WordPress lets anyone bypass auth, install & activate arbitrary plugins, opening the door to remote code execution. Update to 6.72+ now 🔧 Full advisory ➡️ https://volerion.com/vulnerabilities/CVE-2026-1490 #WordPress #infosec #AppSec

    Post summary

    CVE‑2026‑1490 allows attackers to bypass authentication and install arbitrary plugins in CleanTalk Spam Protection for WordPress, potentially enabling remote code execution. A fix is available in version 6.72+, as noted in the full advisory.

    0000082
    51 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Disclosure

    🚨 CRITICAL: CleanTalk Spam Protection plugin flaw (CVSS 9.8) lets attackers install plugins & potentially gain RCE on WordPress sites with invalid API keys. Audit now! https://radar.offseq.com/threat/cve-2026-1490-cwe-350-reliance-on-reverse-dns-reso-0fc3066a #OffSeq #WordPres... https://t.co/LfsaN3KZhe

    Post summary

    The tweet announces a critical RCE vulnerability in the CleanTalk Spam Protection plugin that lets attackers install plugins on WordPress sites with invalid API keys, but it does not mention a PoC, exploit code, patch, or active exploitation.

    0000037
    265 followersView on X

Explore more