CVE · High

CVE-2023-33996 — Spam protection, Honeypot, Anti-Spam by CleanTalk [cleantalk-spam-protect] < 6.11

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-33996 Spam protection, Honeypot, Anti-Spam by CleanTalk [cleantalk-spam-protect] < 6.11 Missing Authorization High 8.8 < 6.11 6.11 2023-06-22

CVE-2023-33996

The CleanTalk spam protection plugin through version 6.10 contains a capability check vulnerability that allows authenticated users with subscriber-level permissions to perform administrative actions without proper authorization. Affected users can modify, export, and import templates, as well as manage comments by trashing or marking them as spam, due to insufficient access control checks and nonce disclosure in multiple plugin functions. The vulnerability impacts all installations running version 6.10 or earlier.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.