CVE-2026-8071 - Spam protection, Honeypot, Anti-Spam by CleanTalk < 6.79 - Unauthenticated Stored XSS via Comment Shortcode Bypass
CVE ID :CVE-2026-8071
Published : June 10, 2026, 7:16 a.m. | 1 hour, 19 minutes ago
Description :The Anti-Spam by CleanTalk. Spam protection WordPress plugin before 6.79 does not properly sanitize content within a custom shortcode used in its email-encoding feature, allowing unauthenticated attackers to inject arbitrary web scripts into approved comments that will execute when any user (including administrators) views the post.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : June 10, 2026, 7:16 a.m. | 1 hour, 19 minutes ago
Description :The Anti-Spam by CleanTalk. Spam protection WordPress plugin before 6.79 does not properly sanitize content within a custom shortcode used in its email-encoding feature, allowing unauthenticated attackers to inject arbitrary web scripts into approved comments that will execute when any user (including administrators) views the post.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...