WordPress Plugin Vulnerabilities

Spam protection, AntiSpam, FireWall by CleanTalk < 6.83 - Unauthenticated Stored Cross-Site Scripting

Description

The plugin does not sanitise and escape some data before outputting it back in a page, leading to a Stored Cross-Site Scripting vulnerability which can be exploited by unauthenticated attackers to inject arbitrary web scripts that will execute when a user views the affected page.

Affects Plugins

References

Classification

Type
XSS
CWE
CVSS

Miscellaneous

Original Researcher
daroo
Verified
No

Timeline

Publicly Published
2026-07-27 (about 28 days ago)
Added
2026-07-30 (about 25 days ago)
Last Updated
2026-07-30 (about 25 days ago)

Other