A critical vulnerability in the WordPress plugin “Spam protection, Honeypot, Anti-Spam by CleanTalk” (aka CleanTalk Anti-Spam) allows unauthenticated arbitrary plugin installation in versions <= 6.71, tracked as CVE-2026-1490 with CVSS 9.8. The flaw is an authorization bypass caused by relying on reverse DNS (PTR) lookups for a security decision in the checkWithoutToken logic; attackers can spoof PTR records to impersonate trusted sources and trigger plugin installation/activation. The issue was reported by researcher Nguyen Ngoc Duc (duc193) of KCSC and published via Wordfence Intelligence; it is noted as exploitable specifically when the site is using an invalid CleanTalk API key.
Successful exploitation enables attackers to install and activate arbitrary plugins, which can be chained into remote code execution (for example, by installing another vulnerable plugin and leveraging it post-install). Separate WordPress plugin CVEs disclosed around the same time include CVE-2026-2001 (WowRevenue <= 2.1.3) enabling authenticated (subscriber+) arbitrary plugin installation via a missing capability check in Notice::install_activate_plugin, and CVE-2026-1750 (Ecwid by Lightspeed Ecommerce Shopping Cart <= 7.0.7) enabling authenticated (subscriber+) privilege escalation by supplying ec_store_admin_access during profile updates due to a missing capability check in save_custom_user_profile_fields; these are distinct issues and not part of the CleanTalk vulnerability.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
By 2026-02-17, public reporting and a Wordfence Intelligence advisory disclosed technical details for CVE-2026-1490, including that attackers could spoof PTR records to appear as cleantalk.org and install or activate arbitrary plugins. The issue was identified by Nguyen Ngoc Duc (duc193) of KCSC and was noted as potentially leading to remote code execution if an additional vulnerable or malicious plugin is installed.
On 2026-02-15, Wordfence received a report describing CVE-2026-1490, an authorization-bypass vulnerability in the WordPress plugin 'Spam protection, Honeypot, Anti-Spam by CleanTalk' affecting versions through 6.71. The flaw stems from reverse DNS (PTR record) spoofing in the checkWithoutToken function and can allow unauthenticated arbitrary plugin installation on sites using an invalid API key.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
thecyberexpress.com
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.