Sceawere
Vulnerability Detail
CVE-2026-39768UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unauthenticated XSS in CleanTalk
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 16h ago
- Vendor
- CleanTalk Inc
- Product
- Security & Malware scan by CleanTalk
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Cross Site Scripting (XSS) in Security & Malware scan by CleanTalk <= 2.189 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-10-06T09:17:49.080Z",
"pubdate": "2026-10-06T09:17:49.080Z",
"executiveSummary": "Security & Malware scan by CleanTalk versions 2.189 and below are susceptible to an unauthenticated Cross-Site Scripting (XSS) vulnerability. This flaw resides in the plugin's handling of user-supplied input, which is improperly sanitized before being reflected in the administrative dashboard or end-user interface.\nThe vulnerability allows an unauthenticated remote attacker to inject malicious JavaScript into the target application. When an administrator or authenticated user views the compromised page, the payload executes within their browser session.\nThe impact includes the potential for session hijacking, unauthorized administrative actions, redirection to malicious domains, and the exfiltration of sensitive configuration data or cookies. Given that the plugin is designed for security monitoring, the exploitation of this vulnerability could lead to the complete compromise of the WordPress site administration. No authentication is required to initiate the attack, significantly increasing the risk profile by allowing opportunistic exploitation by external actors.",
"technicalDetails": "The vulnerability is identified as a Stored or Reflected Cross-Site Scripting (XSS) flaw within the Security & Malware scan by CleanTalk plugin, versions 2.189 and below. The root cause is the failure of the plugin's input handling mechanisms to adequately sanitize or encode data before rendering it to the web browser. The application accepts input via specific HTTP requests and fails to implement necessary output encoding (such as htmlspecialchars or similar sanitization routines), allowing attackers to break out of the HTML context.\nThe attack flow begins with an unauthenticated attacker crafting a malicious payload, typically consisting of JavaScript encapsulated within <script> tags or leveraging event handlers (e.g., onerror, onload) within HTML attributes. By submitting this crafted input to a vulnerable endpoint—likely one used for reporting or logging security findings—the attacker embeds the script into the application state.\nWhen a legitimate administrator or user with higher privileges accesses the dashboard section where this data is rendered, the web browser interprets the injected input as executable code rather than plain text. Because the script executes in the context of the victim's session, the attacker gains the ability to perform actions on behalf of the victim.\nExploitation does not require prior authentication, making the attack surface publicly accessible. The payload behavior is limited only by the attacker's intent; common post-exploitation activities include the acquisition of session tokens via document.cookie, the forced creation of rogue administrative accounts, or the modification of site settings to maintain persistence. Since the Security & Malware scan component often displays logs in the WordPress admin area, the vulnerability is particularly dangerous as it targets the most privileged users of the platform. The lack of sufficient input validation at the entry point combined with inadequate output encoding at the point of presentation ensures that the browser will execute any malicious scripts delivered through the vector."
}