Skip to content
Critical CleanTalk Plugin Vulnerability Enables Authorization Bypass on WordPress

Critical CleanTalk Plugin Vulnerability Enables Authorization Bypass on WordPress

First seen 16 Feb 2026, 16:10 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 16:10 UTC

A critical vulnerability tracked as CVE-2026-1490 has been identified in the CleanTalk plugin for WordPress, allowing for authorization bypass via reverse DNS. This flaw affects thousands of WordPress installations that utilize the plugin for spam filtering and has been assigned a CVSS score of 9.8, indicating its severity.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 210d ago How this analysis works

Timeline

2026-02-15
CVE-2026-1490 published
2026-02-16
Cyberpress and Gbhackers report on the vulnerability

More articles in this cluster (4)

Following this threat?

Track CVE-2026-1490 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed