Impact
The Anti‑Spam by CleanTalk plugin does not properly sanitize or escape the "comment" field, which allows an unauthenticated attacker to inject arbitrary JavaScript. Once a comment from the attacker's address is approved, the payload is stored and executed for any site visitor who views the comment.
Affected Systems
All WordPress installations running the CleanTalk Anti‑Spam plugin version 6.88 or earlier are vulnerable. Site administrators should verify that this plugin is installed and check the installed version against the affected product list from CleanTalk.
Risk and Exploitability
The CVSS score of 5.4 indicates medium overall severity, and the vulnerability is not listed in CISA KEV catalog. No EPSS data is available. The vulnerability can be exploited by any user who submits a comment; on a default WordPress setup the first comment from an email address is approved automatically, so subsequent comments are immediately visible and the malicious script is executed on page load. The attack requires no special privileges.
OpenCVE Enrichment