CVE-2026-8071

The Anti-Spam by CleanTalk. Spam protection WordPress plugin before 6.79 does not properly sanitize content within a custom shortcode used in its email-encoding feature, allowing unauthenticated attackers to inject arbitrary web scripts into approved comments that will execute when any user (including administrators) views the post.
Configurations

No configuration.

History

23 Jul 2026, 09:10

Type Values Removed Values Added
Summary
  • (es) El plugin de WordPress de protección contra el correo no deseado Anti-Spam de CleanTalk, en versiones anteriores a la 6.79, no sanea correctamente el contenido dentro de un shortcode personalizado utilizado en su función de codificación de correo electrónico, lo que permite a atacantes no autenticados inyectar scripts web arbitrarios en comentarios aprobados que se ejecutarán cuando cualquier usuario (incluidos los administradores) vea la publicación.

10 Jun 2026, 11:17

Type Values Removed Values Added
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8

10 Jun 2026, 07:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-10 07:16

Updated : 2026-07-23 09:10


NVD link : CVE-2026-8071

Mitre link : CVE-2026-8071

CVE.ORG link : CVE-2026-8071


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')