SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-19855

MEDIUM · CVSS 6.5 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-09-09 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The CleanTalk WordPress plugin prior to version 6.87 is vulnerable as it allows unauthenticated users to submit comment content that can be executed as server-side shortcodes. This could lead to arbitrary code execution, potentially compromising the integrity of the site and affecting all visitors. WordPress site administrators using this plugin should prioritize updating to mitigate the risk of exploitation.

CVE
CVE-2026-19855
Severity
MEDIUM
CVSS
6.5
EPSS
0.18%
WordPress

Original NVD Description

The CleanTalk WordPress plugin before 6.87 does not prevent unauthenticated, user-supplied comment content from being passed to WordPress's shortcode engine, allowing any visitor to have arbitrary shortcodes registered on the site executed server-side and rendered to every subsequent visitor of the page.