CVE-2026-1490: Critical Reverse DNS Authorization Bypass in the CleanTalk WordPress Plugin
CVE-2026-1490 is a critical authorization bypass vulnerability in the CleanTalk WordPress plugin affecting versions up to 6.71. It allows attackers to spoof reverse DNS (PTR) records to bypass API key validation, potentially permitting unauthenticated users to install arbitrary plugins and execute remote code. Immediate update to version 6.72 is mandatory.