S4E just found a high ssl heart bleed
high·Product Based Web Vulnerabilities·Updated Sep 24, 2025

CVE-2021-24295 Scanner

CVE-2021-24295 Scanner - SQL Injection vulnerability in Spam protection, AntiSpam, FireWall by CleanTalk

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.6k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24295
7.5
CVSS

It was possible to exploit an Unauthenticated Time-Based Blind SQL Injection vulnerability in the Spam protection, AntiSpam, FireWall by CleanTalk WordPress Plugin before 5.153.4. The update_log function in lib/Cleantalk/ApbctWP/Firewall/SFW.php included a vulnerable query that could be injected via the User-Agent Header by manipulating the cookies set by the Spam protection, AntiSpam, FireWall by CleanTalk WordPress plugin before 5.153.4, sending an initial request to obtain a ct_sfw_pass_key cookie and then manually setting a separate ct_sfw_passed cookie and disallowing it from being reset.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Spam protection, AntiSpam, FireWall by CleanTalkby СleanTalk
AFFECTED< 5.153.4SAFE ✓≥ 5.153.4
Updated Aug 21, 2026View on NVD →
Detail

This software is widely used as a WordPress plugin for protecting websites from spam and unwanted content. Developed by CleanTalk, it provides comprehensive protection using various firewall rules and spam filters. The plugin integrates seamlessly with WordPress, offering an easy-to-use interface for website administrators. Its features include comment moderation, form protection, and the ability to combat spam registrations or comments on websites. The plugin is favored by many for its capability to secure websites without affecting the user experience. Constant updates ensure it adapts to the latest threats, making it a reliable choice for website security.

The vulnerability in question is an Unauthenticated Blind SQL Injection in the CleanTalk plugin. This type of vulnerability allows attackers to inject malicious SQL statements into queries, potentially leading to unauthorized access or database manipulation. Before version 5.153.4, the plugin was susceptible to this flaw, which could be exploited through manipulated cookies and HTTP headers. The plugin did not adequately sanitize user inputs, allowing for SQL code execution. Attackers could leverage the User-Agent Header to inject SQL commands, which underscores the severity of this issue. Such vulnerabilities are critical as they can lead to data breaches and unauthorized database access.

The technical details of the vulnerability involve improper sanitization in a specific update_log function. This function resides in the firewall component of the plugin and processes incoming requests. By manipulating cookies such as ct_sfw_pass_key and introducing a ct_sfw_passed cookie, attackers could exploit this to bypass security checks. The vulnerability mainly affects the User-Agent HTTP header, where SQL injection could occur. This action requires no user authentication, making it easy for attackers to bypass traditional access controls. Such technical oversights can be particularly damaging as they provide direct access without proper validation checks.

Exploitation of this vulnerability could lead to severe consequences. Attackers might gain unauthorized access to sensitive information stored within the WordPress database. This could include user credentials, leading to data theft or unauthorized data manipulation. The vulnerability could allow attackers to execute arbitrary SQL commands, potentially degrading database integrity or availability. In some cases, it could further privilege escalation attacks if exploited with other vulnerabilities. Such attacks could compromise the entire website, leading to downtime, data loss, and reputational damage for the website owner.

REFERENCES

Solution Advice
  • Update the Spam protection, AntiSpam, FireWall by CleanTalk plugin to version 5.153.4 or later.
  • Regularly check for and apply security patches and updates for WordPress plugins.
  • Implement web application firewalls to monitor and block suspicious activities.
  • Consider using security plugins that offer additional layers of protection against SQL injections.
  • Regularly audit logs and monitor network traffic for signs of unusual behavior.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-24295 Scanner - SQL Injection vulnerability in Spam protection, AntiSpam, FireWall by CleanTalk S4E