Spam protection, Honeypot, Anti-Spam by CleanTalk < 6.79 - Unauthenticated Stored XSS via Comment Shortcode Bypass
CVE-2026-8071
Currently unrated
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 June 2026
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-8071?
The Anti-Spam by CleanTalk. Spam protection WordPress plugin before 6.79 does not properly sanitize content within a custom shortcode used in its email-encoding feature, allowing unauthenticated attackers to inject arbitrary web scripts into approved comments that will execute when any user (including administrators) views the post.
Affected Version(s)
Anti-Spam by CleanTalk. Spam protection 0 < 6.79
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.