Stored Cross-Site Scripting in Comment SPAM Wiper Plugin for WordPress
CVE-2026-3353
4.4MEDIUM
What is CVE-2026-3353?
The Comment SPAM Wiper plugin for WordPress is susceptible to Stored Cross-Site Scripting due to inadequate input sanitization and output escaping within the 'API Key' setting. This vulnerability potentially allows authenticated attackers with Administrator-level access or higher to inject malicious scripts. These scripts are executed whenever a user accesses the compromised pages. The issue impacts WordPress multi-site installations and those with unfiltered_html disabled, highlighting the importance of maintaining proper security practices and updates.
Affected Version(s)
Comment SPAM Wiper 0 <= 1.2.1