Junglewise Threat Intelligence

CVE-2026-8071: CleanTalk Anti-Spam stored XSS in email-encoding shortcode

CVE-2026-8071 · Severity: info · CVSS 8.8 · Published 2026-06-10

Vendors: CleanTalk.

Executive brief

A popular WordPress anti-spam plugin contains a security flaw that allows attackers to bypass spam filters and inject malicious scripts into website comments. If an administrator or visitor views a page containing one of these malicious comments, the script could execute in their browser, potentially leading to unauthorized actions or account takeover. This risk is particularly high for sites that use the plugin's email-encoding feature to protect contact information.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in the Anti-Spam by CleanTalk plugin due to insufficient sanitization of content within the [apbct_encode_data] custom shortcode. This shortcode is part of the plugin's email-encoding feature, which is active when a valid CleanTalk access key is configured. An unauthenticated attacker can craft a comment containing a broken shortcode structure to inject arbitrary HTML attributes and JavaScript events (e.g., oncontentvisibilityautostatechange). When the comment is rendered on the front-end, the malicious script executes in the context of the viewing user's session. This can lead to session hijacking or administrative actions if triggered by a logged-in admin. The issue is fixed in version 6.79.

Affected products

  • CleanTalk Anti-Spam by CleanTalk < 6.79

Timeline

  • 2026-05-20: disclosed: Public disclosure by researcher
  • 2026-06-10: advisory: NVD publication date
  • 2026-06-10: patched: Fixed in version 6.79

References

Related threats