Description
The CleanTalk WordPress plugin before 6.87 does not prevent unauthenticated, user-supplied comment content from being passed to WordPress's shortcode engine, allowing any visitor to have arbitrary shortcodes registered on the site executed server-side and rendered to every subsequent visitor of the page.
Published: 2026-09-09
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution via Shortcodes
Action: Apply Patch
AI Analysis

Impact

The CleanTalk WordPress plugin prior to version 6.87 fails to sanitise comment content before passing it to WordPress's shortcode engine, allowing any visitor to register and execute arbitrary shortcodes on the site. This flaw permits remote, unauthenticated users to inject code that runs on the server and is rendered in the HTML of subsequent page views, potentially compromising site integrity and delivering malicious content to other visitors.

Affected Systems

The vulnerability affects the CleanTalk WordPress plugin installed on WordPress sites with versions older than 6.87. All sites using the plugin in these versions are susceptible if the comment form is accessible to the public.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity, and the EPSS score of 0.00183 indicates a very low current exploitation probability. The flaw is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is an unauthenticated request to the comment submission endpoint, which processes the input without validation. Successful exploitation would allow attackers to execute server‑side code via shortcodes, affecting confidentiality, integrity, and availability of the site.

Generated by OpenCVE AI on September 9, 2026 at 18:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade CleanTalk to version 6.87 or later to patch the shortcode sanitation flaw
  • Disable or restrict WordPress shortcode processing on comment content, for example by configuring the plugin or modifying theme functions to strip shortcodes from comments
  • Sanitize comment input by removing or escaping all untrusted shortcode tags before submission

Generated by OpenCVE AI on September 9, 2026 at 18:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-74
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Description The CleanTalk WordPress plugin before 6.87 does not prevent unauthenticated, user-supplied comment content from being passed to WordPress's shortcode engine, allowing any visitor to have arbitrary shortcodes registered on the site executed server-side and rendered to every subsequent visitor of the page.
Title Spam protection, Honeypot, Anti-Spam by CleanTalk < 6.87 - Unauthenticated Arbitrary Shortcode Execution via Comment Text
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-09T15:23:18.450Z

Reserved: 2026-08-14T09:43:54.757Z

Link: CVE-2026-19855

cve-icon Vulnrichment

Updated: 2026-09-09T15:21:52.853Z

cve-icon NVD

Status : Deferred

Published: 2026-09-09T07:16:56.500

Modified: 2026-09-09T16:17:02.250

Link: CVE-2026-19855

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T18:15:13Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')