ZeroHour

CVE-2026-77830

large

Stored XSS in CleanTalk Anti-Spam WordPress Plugin via Comment Placeholder

CVSS 3.1
7.2 high
EPSS
<1%p19
Published
()
Modified
AI analysis

The Spam protection, Honeypot, Anti-Spam by CleanTalk WordPress plugin, in all versions up to and including 6.86, fails to adequately sanitize and escape the Comment Content aria-label placeholder, allowing arbitrary web scripts to be stored in pages. The payload can be delivered through an unauthenticated comment submission, and when comment moderation is enabled, an approving moderator must first publish the comment before the injected script reaches other users. Once the comment is live, the injected script executes in the browsers of non-logged-in visitors only, letting an attacker run arbitrary JavaScript against anonymous visitors, such as redirecting them, injecting malicious content, or performing actions in their session context. Any WordPress site running the plugin at version 6.86 or earlier is affected. No public proof-of-concept exists, the flaw is not in CISA's KEV, and EPSS indicates a low (~0.3%) probability of exploitation in the next 30 days, so no exploitation is currently known.

What to do: Update the CleanTalk anti-spam plugin to a version newer than 6.86 (the latest patched release). Until patched, consider holding comments in moderation and reviewing the moderation queue for comments containing HTML or script-like content before approving, and avoid approving unfamiliar comments. Note that logged-in users (including moderators and commenters) will not trigger the injected script, so test affected pages in a logged-out browser when verifying.

Affected
CleanTalk Spam protection, Honeypot, Anti-Spam by CleanTalk (WordPress plugin)all versions up to and including 6.86
Estimated exposure
largehundreds of thousands of WordPress sites (order of ~200,000+ sites) — Estimated from the plugin's large active-install base on WordPress.org, on the order of 200,000+ sites, though the number actually reachable depends on whether comments are open; this is an estimate, not a figure from the CVE data.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The Spam protection, Honeypot, Anti-Spam by CleanTalk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content aria-label Placeholder in all versions up to, and including, 6.86 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with custom-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload is deliverable via unauthenticated comment submission and executes exclusively for non-logged-in visitors; if comment moderation is enabled, an approving moderator must first publish the comment before the script reaches other users.

Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.