Description
The Anti-Spam by CleanTalk – Spam Protection Without CAPTCHA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'comment' parameter in all versions up to, and including, 6.88 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability is exploitable once a comment from the attacker's email address has been approved; on default WordPress installations, only the first comment from a given email address is held for moderation, meaning subsequent comments auto-approve and immediately expose the payload to site visitors.
Published: 2026-10-10
Score: 5.4 Medium
EPSS: n/a
KEV: No
Impact: Stored Cross‑Site Scripting (XSS)
Action: Apply Patch
AI Analysis

Impact

The Anti‑Spam by CleanTalk plugin does not properly sanitize or escape the "comment" field, which allows an unauthenticated attacker to inject arbitrary JavaScript. Once a comment from the attacker's address is approved, the payload is stored and executed for any site visitor who views the comment.

Affected Systems

All WordPress installations running the CleanTalk Anti‑Spam plugin version 6.88 or earlier are vulnerable. Site administrators should verify that this plugin is installed and check the installed version against the affected product list from CleanTalk.

Risk and Exploitability

The CVSS score of 5.4 indicates medium overall severity, and the vulnerability is not listed in CISA KEV catalog. No EPSS data is available. The vulnerability can be exploited by any user who submits a comment; on a default WordPress setup the first comment from an email address is approved automatically, so subsequent comments are immediately visible and the malicious script is executed on page load. The attack requires no special privileges.

Generated by OpenCVE AI on October 10, 2026 at 05:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the CleanTalk Anti‑Spam plugin to the latest version, which removes the vulnerable Greedy Regex implementation.
  • Delete or sanitize any existing comments that contain malicious script payloads to ensure the XSS code is not served to visitors.
  • Disable or remove the CleanTalk plugin until an update is applied, and consider tightening comment approval rules to prevent auto‑approval of unauthenticated user input.

Generated by OpenCVE AI on October 10, 2026 at 05:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 04:30:00 +0000

Type Values Removed Values Added
Description The Anti-Spam by CleanTalk – Spam Protection Without CAPTCHA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'comment' parameter in all versions up to, and including, 6.88 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability is exploitable once a comment from the attacker's email address has been approved; on default WordPress installations, only the first comment from a given email address is held for moderation, meaning subsequent comments auto-approve and immediately expose the payload to site visitors.
Title Anti-Spam by CleanTalk <= 6.88 - Unauthenticated Stored Cross-Site Scripting via Comment Content via ContactsEncoder Greedy Regex
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-10T04:26:46.788Z

Reserved: 2026-09-30T14:52:17.547Z

Link: CVE-2026-103424

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T05:16:39.003

Modified: 2026-10-10T05:16:39.003

Link: CVE-2026-103424

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T06:00:12Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')