CVE-2024-10542 vulnerability and BitFire protection

How BitFire Blocks CVE-2024-10542: CleanTalk Anti-Spam Authorization Bypass

WordPress vulnerability research

BitFire PRO RASP blocks CVE-2024-10542, an unauthenticated plugin-installation flaw in CleanTalk Anti-Spam, at runtime. Update to 6.44 and investigate.

Unauthenticated CVSS 9.8 Critical Remote Code Execution Authorization Bypass
BitFire · Vulnerability advisoryResearch published
AdvisoryCVE-2024-10542
ComponentAnti-Spam by CleanTalk – Spam Protection Without CAPTCHA
Relevant sourcelib/Cleantalk/ApbctWP/RemoteCalls.php — RemoteCalls::checkWithoutToken() (lines 34–48) and RemoteCalls::perform() (lines 78–83)
Executive summary

What WordPress administrators need to know

CVE-2024-10542 is a critical (CVSS 9.8) authorization bypass in Anti-Spam by CleanTalk 6.43.2 and below. The plugin's remote-maintenance channel authorized privileged actions by checking whether the client's reverse DNS merely contained 'cleantalk.org' — a gate an attacker satisfies by controlling their own PTR records. An unauthenticated request could then trigger WordPress admin-only plugin installation and activation, which the disclosure links to remote code execution. BitFire PRO RASP stops the exploit at runtime: the administrator credential-evidence guard rejects the credential-free privileged operation, and the filesystem guard blocks the unauthorized PHP write into wp-content/plugins. Update to 6.44 and investigate for persistence.

At a glance

Key facts

  • Unauthenticated remote-call dispatch on the init hook requires no WordPress login, nonce, or capability.
  • Authorization fell back to a spoofable reverse-DNS substring test ('cleantalk.org') evaluated against an IP that could be header-influenced behind proxies.
  • The token-free path additionally required the site's stored CleanTalk access key state to be invalid or unvalidated.
  • Passing requests ran admin-only install_plugin and activate_plugin remote calls, writing plugin PHP into wp-content/plugins and activating it.
  • Fixed in 6.44: exact-match NOC hostname allowlist, REMOTE_ADDR-only IP source, and a strict two-action token-free allowlist.
  • BitFire PRO RASP blocks both the credential-free administrator operation and the unauthorized PHP write at runtime.
01
Vulnerability overview

Understand the exposure

The affected component, attack path, and practical risk for WordPress websites.

Affected componentAnti-Spam by CleanTalk – Spam Protection Without CAPTCHA
Potential reach200000 installations
Attack techniqueauthorization bypass
Published2026-10-09
BitFire PRO RASP stops CVE-2024-10542 where it counts: the unauthenticated PHP write into wp-content/plugins never lands, and the credential-free administrator operation never runs.
02
Technical analysis

How the vulnerability works

Research details, affected versions, exploitation behavior, and remediation guidance.

A Spoofable Hostname Replaced Real Authorization

CleanTalk's `RemoteCalls` class exposes privileged maintenance actions on WordPress's `init` hook, reachable by GET or POST whenever request parameters indicate a remote call — no login, nonce, or capability required. Without a valid access-key token, `checkWithoutToken()` substituted a network heuristic for real authorization: a client counted as a trusted CleanTalk NOC server if the reverse DNS of its IP merely contained the substring `cleantalk.org`, provided the site's stored key state was invalid or unvalidated. Attackers control their own PTR records, and proxied setups could feed the check a header-influenced IP, so the deciding input was not the connection peer. A passing request dispatched admin-only actions such as `install_plugin` and `activate_plugin` with no authenticated user; per the disclosure, activating a known-vulnerable plugin then yields remote code execution.

BitFire PRO RASP: No Credentials, No Administrator Operation

The heart of this exploit is not malicious input — it is a privileged operation performed by an operator who does not exist. The entire chain runs outside any authenticated WordPress session: no logged-in cookie, no application password, no capability check. **BitFire PRO RASP**'s administrator credential-evidence guard requires real authentication evidence at the protected operation itself. When the token-free remote call attempts administrator-equivalent work — plugin installation, activation, settings updates — with no valid WordPress credentials behind it, BitFire PRO blocks the operation outright. It does not need to recognize CVE-2024-10542 to do so; it enforces the trust boundary the substring test abandoned. The forged maintenance request never executes as an administrator.

BitFire PRO RASP Stops the Unauthorized Plugin Write

Even with dispatch achieved, impact depends on new PHP landing on disk. `apbct_rc__install_plugin()` resolves the attacker-chosen slug against the WordPress.org plugin API and calls `Plugin_Upgrader->install($download_link)`, writing plugin PHP files into `wp-content/plugins` without authentication; `activate_plugins()` makes them executable on the next request. **BitFire PRO RASP** filesystem protection inspects PHP-file writes and blocks unauthorized creation or modification of PHP — explicitly including plugin-installation payloads. The unauthenticated install never becomes persistent, executable code, so the remote-code-execution route described in the disclosure is severed at the write itself, not merely filtered at the door.

If Your Site Was Affected, Investigate for Persistence

Update CleanTalk Anti-Spam to 6.44 or later immediately. The patch is decisive: NOC-origin checks now demand a strict exact match against two hard-coded CleanTalk hostnames, resolved from `$_SERVER['REMOTE_ADDR']` rather than a header-influenced IP, and `perform()` additionally requires the requested action to appear in a two-entry token-free allowlist — `get_fresh_wpnonce` and `post_api_key`. Install, activation, and settings remote calls can no longer run token-free under any circumstance. Patching closes the known path; it does not undo a compromise that already occurred. If your site ran 6.43.2 or older with an invalid or unvalidated access key, run **BitFire Threat Hunter** now. It hunts down backdoor administrator accounts, hidden database triggers, long-running PHP processes, and droppers that reinstall malware. Remove every persistence mechanism found and rotate WordPress administrator credentials.

Patch, Verify, and Let BitFire Hold the Line

CVE-2024-10542 turned a spam plugin's maintenance channel into an unauthenticated plugin-installation primitive — and a credible route to remote code execution. **BitFire PRO RASP** is built for exactly this failure shape: it blocks credential-free administrator operations and unauthorized PHP writes at runtime, even for exploits no signature has ever seen. Update to 6.44 today, investigate with Threat Hunter if you were exposed, and put BitFire PRO in front of your WordPress stack. Install BitFire and stop the next exploit before it executes.

03
Source review

Vulnerable and fixed code

The relevant source is located in lib/Cleantalk/ApbctWP/RemoteCalls.php — RemoteCalls::checkWithoutToken() (lines 34–48) and RemoteCalls::perform() (lines 78–83).

BeforeVulnerable behavior
    public static function checkWithoutToken()
    {
        global $apbct;

        $is_noc_request = ! $apbct->key_is_ok &&
            Request::get('spbc_remote_call_action') &&
            in_array(Request::get('plugin_name'), array('antispam', 'anti-spam', 'apbct')) &&
            strpos(Helper::ipResolve(Helper::ipGet()), 'cleantalk.org') !== false;

        // no token needs for this action, at least for now
        // todo Probably we still need to validate this, consult with analytics team
        $is_wp_nonce_request = $apbct->key_is_ok && Request::get('spbc_remote_call_action') === 'get_fresh_wpnonce';

        return $is_wp_nonce_request || $is_noc_request;
    }
AfterCorrected behavior
    public static function checkWithoutToken()
    {
        global $apbct;

        $rc_servers = [
            'netserv3.cleantalk.org',
            'netserv4.cleantalk.org',
        ];

        $is_noc_request = ! $apbct->key_is_ok &&
            Request::get('spbc_remote_call_action') &&
            in_array(Request::get('plugin_name'), array('antispam', 'anti-spam', 'apbct')) &&
            in_array(Helper::ipResolve(Helper::ipGet('remote_addr')), $rc_servers, true);

        // no token needs for this action, at least for now
        // todo Probably we still need to validate this, consult with analytics team
        $is_wp_nonce_request = $apbct->key_is_ok && Request::get('spbc_remote_call_action') === 'get_fresh_wpnonce';

        return $is_wp_nonce_request || $is_noc_request;
04
Zero-day protection

Protection from the first exploit request

BitFire protects WordPress servers on day zero—before a vulnerability is publicly known and before other vendors have time to develop signatures or patches.

01 · VerifyStop unknown clients

Bot controls and browser verification stop untrusted automated clients before previously unknown exploit code reaches WordPress.

02 · DetectBlock malicious behavior

General WAF protections identify dangerous request behavior and hostile payloads without waiting for a vulnerability-specific signature.

03 · PreventContain attacks at runtime

RASP follows execution inside PHP and prevents unauthorized changes to protected files, accounts, and database content.

BitFire · WordPress protectionZero-day ready
BitFire zero-day WordPress vulnerability protection
BitFire combines verified-client controls, behavior-based WAF detection, and runtime RASP enforcement to protect WordPress before an exploit has a name, CVE, signature, or vendor patch.
About the author

Cory Marsh

Cory has more than 20 years of internet security experience and is a lead developer on the BitFire project.

Read BitFire security research →
Protect your WordPress website

Add protection before the next exploit arrives.

BitFire combines bot controls, request inspection, malware detection, and runtime protection in one WordPress security platform.

Protect my site free →