Impact
This vulnerability stems from insufficient input sanitization and output escaping within the Spam protection, Honeypot, Anti‑Spam by CleanTalk WordPress plugin. An attacker can craft a comment containing JavaScript that is inserted into the comment's 'aria-label' placeholder, resulting in stored cross‑site scripting. When other visitors load the page, the script executes in their browsers, potentially leading to defacement, credential theft, or malicious redirects. The flaw is limited to client‑side execution and requires only the ability to submit a comment, though moderation approval is required if comment moderation is enabled.
Affected Systems
All WordPress sites running the CleanTalk Spam protection, Honeypot, Anti‑Spam plugin version 6.86 or earlier are affected. Sites using any later releases are not vulnerable.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.2, indicating moderate to high severity. No EPSS score is available, so the likelihood of exploitation cannot be precisely quantified, but client‑side XSS is a common attack vector and is not listed in the CISA KEV catalog. The intended attack path involves an authenticated attacker with custom or higher privileges, or a malicious user who can bypass comment moderation, submitting a malicious payload that will be rendered for non‑logged‑in users once the comment is approved.
OpenCVE Enrichment