The “Spam protection, AntiSpam, FireWall by CleanTalk” anti-spam WordPress plugin could expose sensitive user data to an unauthorized attacker. A SQL Injection vulnerability in the Anti-spam WordPress plugin, known as CVE-2021-24295, could be used by a criminal to gain access to user data, such as: emails, passwords, credit card details, and more.
See also: WordPress: Added to the list of those opposing Google FLoC

The Spam protection, AntiSpam, FireWall by CleanTalk WordPress plugin has over 100,000 installations. The plugin allows filtering spam and trash comments on sites using the WordPress CMS.
“On March 4, 2021, the Wordfence Threat Intelligence team disclosed a Time-Based Blind SQL Injection vulnerability found in Spam protection, AntiSpam, FireWall by CleanTalk, a WordPress plugin, which is installed on more than 100,000 sites. This vulnerability could be used to extract sensitive information from a site’s database, including emails and password hashes, without connecting to the site,” Wordfence reports.
The SQL Injection vulnerability is very serious and is rated 7.5/10.
The plugin protects sites from spam comments by maintaining a blocklist and monitoring the behavior of different IP addresses.
See also: Brizy Page Builder Review: One of the Top Builders for WordPress
Unfortunately, the update_log function in lib/Cleantalk/ApbctWP/Firewall/SFW.php, which was used to insert records of these requests into the database, failed to use a prepared SQL statement.
SQL injection vulnerability allows attackers to interfere with the queries an application makes to its database, in order to intercept or influence the responses returned by the databases. Prepared statements help prevent these attacks.

Researchers successfully exploited a vulnerability in the Anti-Spam WordPress Plugin through a time-based blind SQL-injection technique. This is an approach that involves sending requests to the database that “guess” the contents of a database table and instructing the database to delay the response if the guess is correct.
See also: WordPress: Pirated themes and plugins "threaten" sites!
“For example, a request might ask the database if the first letter of the administrator’s email address starts with the letter “c” and instruct it to delay the response by five seconds if that is true, and then try to guess the next letters,” Wordfence said.
Wordfence also described several features in the WordPress Plugin code that make it difficult to exploit the vulnerability. However, the problem still exists. Therefore, webmasters should use the updated version of the plugin, 5.153.4, to protect themselves.
Source: Threatpost
