WordPress Plugin Vulnerabilities

Spam protection, Honeypot, Anti-Spam by CleanTalk < 6.79 - Unauthenticated Stored XSS via Comment Shortcode Bypass

Description

The plugin does not properly sanitize content within a custom shortcode used in its email-encoding feature, allowing unauthenticated attackers to inject arbitrary web scripts into approved comments that will execute when any user (including administrators) views the post.

Proof of Concept

Affects Plugins

References

Classification

Type
XSS
CWE
CVSS

Miscellaneous

Original Researcher
Matthew Rollings
Submitter
Matthew Rollings
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2026-05-20 (about 21 days ago)
Added
2026-05-20 (about 20 days ago)
Last Updated
2026-06-09 (about 9 hours ago)

Other