WordPress Plugin Vulnerabilities
Spam protection, AntiSpam, FireWall by CleanTalk < 6.83 - Unauthenticated Stored Cross-Site Scripting
Description
The plugin does not sanitise and escape some data before outputting it back in a page, leading to a Stored Cross-Site Scripting vulnerability which can be exploited by unauthenticated attackers to inject arbitrary web scripts that will execute when a user views the affected page.
Affects Plugins
References
Classification
Type
XSS
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
daroo
Verified
No
WPVDB ID
Timeline
Publicly Published
2026-07-27 (about 28 days ago)
Added
2026-07-30 (about 25 days ago)
Last Updated
2026-07-30 (about 25 days ago)