Impact
The CleanTalk WordPress plugin prior to version 6.87 fails to sanitise comment content before passing it to WordPress's shortcode engine, allowing any visitor to register and execute arbitrary shortcodes on the site. This flaw permits remote, unauthenticated users to inject code that runs on the server and is rendered in the HTML of subsequent page views, potentially compromising site integrity and delivering malicious content to other visitors.
Affected Systems
The vulnerability affects the CleanTalk WordPress plugin installed on WordPress sites with versions older than 6.87. All sites using the plugin in these versions are susceptible if the comment form is accessible to the public.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, and the EPSS score of 0.00183 indicates a very low current exploitation probability. The flaw is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is an unauthenticated request to the comment submission endpoint, which processes the input without validation. Successful exploitation would allow attackers to execute server‑side code via shortcodes, affecting confidentiality, integrity, and availability of the site.
OpenCVE Enrichment