Executive brief
A security vulnerability exists in the CleanTalk AntiSpam and Firewall plugin for WordPress, which is used to protect websites from spam and malicious traffic. An unauthenticated attacker could trick a site administrator into clicking a malicious link, allowing the attacker to execute unauthorized scripts in the administrator's browser. This could lead to unauthorized website changes, theft of session information, or redirection of visitors to malicious sites.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in the CleanTalk Spam protection, AntiSpam, FireWall plugin for WordPress (versions <= 6.82) due to improper neutralization of input during web page generation (CWE-79). The flaw allows an unauthenticated remote attacker to inject malicious scripts into the application. Successful exploitation requires a privileged user to perform an action, such as clicking a crafted link or visiting a malicious page (User Interaction required). Once executed, the script can perform actions in the context of the victim's browser, potentially leading to session hijacking or site defacement. The issue is resolved in version 6.83.
Affected products
- CleanTalk Inc Spam protection, AntiSpam, FireWall by CleanTalk <= 6.82
Timeline
- 2026-06-24: disclosed: Reported by daroo to Patchstack
- 2026-07-27: advisory: Published by Patchstack and NVD
- 2026-07-27: patched: Version 6.83 released to address the vulnerability