A Spoofable Hostname Replaced Real Authorization
CleanTalk's `RemoteCalls` class exposes privileged maintenance actions on WordPress's `init` hook, reachable by GET or POST whenever request parameters indicate a remote call — no login, nonce, or capability required. Without a valid access-key token, `checkWithoutToken()` substituted a network heuristic for real authorization: a client counted as a trusted CleanTalk NOC server if the reverse DNS of its IP merely contained the substring `cleantalk.org`, provided the site's stored key state was invalid or unvalidated. Attackers control their own PTR records, and proxied setups could feed the check a header-influenced IP, so the deciding input was not the connection peer. A passing request dispatched admin-only actions such as `install_plugin` and `activate_plugin` with no authenticated user; per the disclosure, activating a known-vulnerable plugin then yields remote code execution.
BitFire PRO RASP: No Credentials, No Administrator Operation
The heart of this exploit is not malicious input — it is a privileged operation performed by an operator who does not exist. The entire chain runs outside any authenticated WordPress session: no logged-in cookie, no application password, no capability check. **BitFire PRO RASP**'s administrator credential-evidence guard requires real authentication evidence at the protected operation itself. When the token-free remote call attempts administrator-equivalent work — plugin installation, activation, settings updates — with no valid WordPress credentials behind it, BitFire PRO blocks the operation outright. It does not need to recognize CVE-2024-10542 to do so; it enforces the trust boundary the substring test abandoned. The forged maintenance request never executes as an administrator.
BitFire PRO RASP Stops the Unauthorized Plugin Write
Even with dispatch achieved, impact depends on new PHP landing on disk. `apbct_rc__install_plugin()` resolves the attacker-chosen slug against the WordPress.org plugin API and calls `Plugin_Upgrader->install($download_link)`, writing plugin PHP files into `wp-content/plugins` without authentication; `activate_plugins()` makes them executable on the next request. **BitFire PRO RASP** filesystem protection inspects PHP-file writes and blocks unauthorized creation or modification of PHP — explicitly including plugin-installation payloads. The unauthenticated install never becomes persistent, executable code, so the remote-code-execution route described in the disclosure is severed at the write itself, not merely filtered at the door.
If Your Site Was Affected, Investigate for Persistence
Update CleanTalk Anti-Spam to 6.44 or later immediately. The patch is decisive: NOC-origin checks now demand a strict exact match against two hard-coded CleanTalk hostnames, resolved from `$_SERVER['REMOTE_ADDR']` rather than a header-influenced IP, and `perform()` additionally requires the requested action to appear in a two-entry token-free allowlist — `get_fresh_wpnonce` and `post_api_key`. Install, activation, and settings remote calls can no longer run token-free under any circumstance. Patching closes the known path; it does not undo a compromise that already occurred. If your site ran 6.43.2 or older with an invalid or unvalidated access key, run **BitFire Threat Hunter** now. It hunts down backdoor administrator accounts, hidden database triggers, long-running PHP processes, and droppers that reinstall malware. Remove every persistence mechanism found and rotate WordPress administrator credentials.
Patch, Verify, and Let BitFire Hold the Line
CVE-2024-10542 turned a spam plugin's maintenance channel into an unauthenticated plugin-installation primitive — and a credible route to remote code execution. **BitFire PRO RASP** is built for exactly this failure shape: it blocks credential-free administrator operations and unauthorized PHP writes at runtime, even for exploits no signature has ever seen. Update to 6.44 today, investigate with Threat Hunter if you were exposed, and put BitFire PRO in front of your WordPress stack. Install BitFire and stop the next exploit before it executes.