Sceawere
Vulnerability Detail
CVE-2026-103424UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
CleanTalk Stored Cross-Site Scripting
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.4
- Creation Date
- 3h ago
- Vendor
- cleantalk
- Product
- Anti-Spam by CleanTalk – Spam Protection Without CAPTCHA
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
The Anti-Spam by CleanTalk – Spam Protection Without CAPTCHA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'comment' parameter in all versions up to, and including, 6.88 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability is exploitable once a comment from the attacker's email address has been approved; on default WordPress installations, only the first comment from a given email address is held for moderation, meaning subsequent comments auto-approve and immediately expose the payload to site visitors.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.4",
"pubDate": "2026-10-10T05:16:39.003Z",
"pubdate": "2026-10-10T05:16:39.003Z",
"executiveSummary": "The Anti-Spam by CleanTalk plugin for WordPress, in versions up to and including 6.88, is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. This flaw arises from inadequate input sanitization and output escaping within the 'comment' parameter. The vulnerability allows unauthenticated attackers to inject and store malicious JavaScript payloads within the application's database. When a site administrator or user views the affected page containing the malicious comment, the script executes within the context of the victim's browser session. This can lead to unauthorized actions, session hijacking, or the defacement of the affected website. The exploitability is heightened by WordPress's default comment moderation settings; after an initial comment from an attacker is approved, subsequent comments from the same email address are typically auto-approved, allowing for the immediate and automatic deployment of payloads. The risk is critical for sites that allow public comments, as it provides a pathway for unauthenticated remote attackers to compromise user sessions or exfiltrate sensitive data.",
"technicalDetails": "The vulnerability originates from a failure to perform adequate input validation and context-aware output encoding on the 'comment' parameter processed by the Anti-Spam by CleanTalk plugin. Specifically, the plugin fails to sanitize user-supplied input before it is persisted in the WordPress database, allowing for the injection of arbitrary HTML and JavaScript tags. When these comments are rendered on the front end of the WordPress site, the browser interprets the injected script as legitimate code rather than inert text.\nThe attack flow begins with an unauthenticated attacker submitting a crafted comment containing a malicious payload via the comment form. In a standard WordPress configuration, the first comment submitted by a unique email address is routed to the moderation queue. Once the attacker's email address is validated or their first comment is manually approved by an administrator, the plugin's interaction with the WordPress comment system triggers a logic bypass for subsequent submissions. Because WordPress often auto-approves follow-up comments from previously approved email addresses, the attacker can bypass moderation checks entirely.\nOnce the comment is published, any user viewing the page containing the comment will execute the stored script. The payload operates within the victim's browser, enabling the attacker to perform actions on behalf of the user, such as hijacking session cookies, stealing authentication tokens, or injecting additional malicious content into the site's DOM. Because this is a stored XSS vulnerability, the payload remains persistent on the server until the comment is manually removed by an administrator. This lack of sanitization at the point of injection and lack of output encoding at the point of display represents a significant failure in the plugin's data handling lifecycle, affecting all versions up to 6.88."
}