SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-77830

HIGH · CVSS 7.2 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-09-05 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Spam protection, Honeypot, Anti-Spam by CleanTalk plugin for WordPress is susceptible to Stored Cross-Site Scripting due to inadequate input sanitization and output escaping in the comment content. This vulnerability allows authenticated attackers to inject malicious scripts that execute for non-logged-in users, potentially compromising user data and site integrity. WordPress site administrators using this plugin should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-77830
Severity
HIGH
CVSS
7.2
EPSS
0.27%
WordPress

Original NVD Description

The Spam protection, Honeypot, Anti-Spam by CleanTalk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content aria-label Placeholder in all versions up to, and including, 6.86 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with custom-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload is deliverable via unauthenticated comment submission and executes exclusively for non-logged-in visitors; if comment moderation is enabled, an approving moderator must first publish the comment before the script reaches other users.