Description
Unauthenticated Cross Site Scripting (XSS) in Spam protection, AntiSpam, FireWall by CleanTalk <= 6.82 versions.
Published: 2026-07-27
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is an unauthenticated Cross Site Scripting flaw in the WordPress Spam protection, AntiSpam, FireWall by CleanTalk plugin, impacting all versions up to and including 6.82. An attacker who can submit content to the site can inject malicious JavaScript that will execute in the browser of any user viewing the affected page. The injection can be used to steal session cookies, deface the site, or redirect visitors to malicious sites. The flaw is identified as CWE‑79, an input validation weakness that allows unsanitized data to be reflected or stored.

Affected Systems

Affected systems are WordPress installations that use the CleanTalk Spam protection, AntiSpam, FireWall by CleanTalk plugin version 6.82 or earlier. The vulnerability exists in all releases from the first version up to and including 6.82; updates to 6.83 or later eliminate the flaw.

Risk and Exploitability

The CVSS score for this issue is 7.1, indicating a high severity. The EPSS score of <1% (0.00146) indicates a very low but non‑zero likelihood of exploitation. Despite this low probability, the lack of authentication and ability to inject arbitrary script make it a strong target for attackers. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves any actor who can submit data to the plugin’s input fields, such as comment areas or spam‑filter interfaces.

Generated by OpenCVE AI on August 3, 2026 at 15:38 UTC.

Remediation

Vendor Solution

Update the WordPress Spam protection, AntiSpam, FireWall by CleanTalk Plugin to the latest available version (at least 6.83).


OpenCVE Recommended Actions

  • Upgrade the WordPress Spam protection, AntiSpam, FireWall by CleanTalk plugin to version 6.83 or newer.
  • If an upgrade cannot be performed immediately, disable or uninstall the vulnerable plugin to eliminate the XSS surface.
  • Apply a web application or plugin firewall rule to block suspicious script payloads delivered through the plugin’s input fields during the transition period.

Generated by OpenCVE AI on August 3, 2026 at 15:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Cleantalk
Cleantalk spam Protection, Antispam, Firewall
Wordpress
Wordpress wordpress
Vendors & Products Cleantalk
Cleantalk spam Protection, Antispam, Firewall
Wordpress
Wordpress wordpress

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in Spam protection, AntiSpam, FireWall by CleanTalk <= 6.82 versions.
Title WordPress Spam protection, AntiSpam, FireWall by CleanTalk plugin <= 6.82 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Cleantalk Spam Protection, Antispam, Firewall
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-28T13:52:02.436Z

Reserved: 2026-07-22T08:52:41.029Z

Link: CVE-2026-65437

cve-icon Vulnrichment

Updated: 2026-07-28T13:51:58.645Z

cve-icon NVD

Status : Deferred

Published: 2026-07-27T23:16:41.540

Modified: 2026-07-28T16:19:12.780

Link: CVE-2026-65437

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T15:45:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')