Get a Pentest and security assessment of your IT network.

Cyber Security

Anti-Spam WordPress Plugin Could Expose Website User Data

Spam protection, AntiSpam, FireWall by CleanTalk is installed on more than 100,000 sites. The issue (CVE-2021-24295, which carries a high-severity CVSS vulnerability rating of 7.5 out of 10) arises thanks to how it performs that filtering. It maintains a blocklist and tracks the behavior of different IP addresses, including the user-agent string that browsers send to identify themselves. Researchers were able to successfully exploit the vulnerability via the time-based vulnerability in CleanTalk.

Source: https://threatpost.com/anti-spam-wordpress-plugin-expose-data/165901/

Related posts
Cyber Security

Zip Codes & PII: Are They Personal Data?

Cyber Security

Zero-Day Vulnerabilities: User Defence Guide

Cyber Security

Zero Knowledge Voting with Trusted Server

Cyber Security

ZeroNet: 51% Attack Risks & Mitigation