CVE-2026-8071

The Anti-Spam by CleanTalk. Spam protection WordPress plugin before 6.79 does not properly sanitize content within a custom shortcode used in its email-encoding feature, allowing unauthenticated attackers to inject arbitrary web scripts into approved comments that will execute when any user (including administrators) views the post.
CVSS

No CVSS.

Configurations

No configuration.

History

10 Jun 2026, 07:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-10 07:16

Updated : 2026-06-10 07:16


NVD link : CVE-2026-8071

Mitre link : CVE-2026-8071

CVE.ORG link : CVE-2026-8071


JSON object : View

Products Affected

No product.

CWE

No CWE.