CVE-2023-33996
The CleanTalk spam protection plugin through version 6.10 contains a capability check vulnerability that allows authenticated users with subscriber-level permissions to perform administrative actions without proper authorization. Affected users can modify, export, and import templates, as well as manage comments by trashing or marking them as spam, due to insufficient access control checks and nonce disclosure in multiple plugin functions. The vulnerability impacts all installations running version 6.10 or earlier.
Based on public CVE data (MITRE/NVD).