情シスマン®【公式】USEN GATE 02[verified]@joshisuman_usenGeneral
A tweet announces a serious CVE-2026-1490 flaw in the CleanTalk WordPress plugin, warning that up to 200,000 sites might be impacted, but offers no exploit details, PoC, or mitigation advice.
Netlas.io[verified]@Netlas_ioDisclosure
CVE-2026-1490 is a new vulnerability in the CleanTalk WordPress plugin that permits attackers to install arbitrary plugins, potentially enabling further attacks.
Quttera - eCommerce Security[verified]@MNovofastovskyPatch
A critical authorization bypass in CleanTalk Anti‑Spam (≤6.71) lets unauthenticated attackers install arbitrary plugins, potentially leading to RCE; users must update or remove the plugin and enforce valid API keys.
ThreatCluster[verified]@threatclusterPatch
The text announces CVE-2026-1490, a high‑severity authorization bypass flaw in the CleanTalk WordPress plugin, and urges administrators to patch affected sites.
OffSeq | Adversary Tactics for Cyber Resilience[verified]@offseqDisclosure
The tweet announces CVE‑2026‑1490 as a critical flaw enabling unauthorized plugin installations on CleanTalk‑protected WordPress sites by bypassing API key validation, urging administrators to audit promptly.
Volerion[verified]@VolerionSecPatch
CVE‑2026‑1490 allows attackers to bypass authentication and install arbitrary plugins in CleanTalk Spam Protection for WordPress, potentially enabling remote code execution. A fix is available in version 6.72+, as noted in the full advisory.
OffSeq | Adversary Tactics for Cyber Resilience[verified]@offseqDisclosure
The tweet announces a critical RCE vulnerability in the CleanTalk Spam Protection plugin that lets attackers install plugins on WordPress sites with invalid API keys, but it does not mention a PoC, exploit code, patch, or active exploitation.
Gray Hats@the_yellow_fallPatch
CVE-2026-1490 is a critical RCE flaw in CleanTalk that allows DNS spoofing and authentication bypass, affecting roughly 200,000 WordPress sites. Users are advised to update to version 6.72 immediately.