Vulnerability Description
The Anti-Spam by CleanTalk. Spam protection WordPress plugin before 6.79 does not properly sanitize content within a custom shortcode used in its email-encoding feature, allowing unauthenticated attackers to inject arbitrary web scripts into approved comments that will execute when any user (including administrators) views the post.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-8071?
CVE-2026-8071 is a vulnerability with a CVSS score of 8.8 (HIGH). The Anti-Spam by CleanTalk. Spam protection WordPress plugin before 6.79 does not properly sanitize content within a custom shortcode used in its email-encoding feature, allowing unauthenticated attac...
How severe is CVE-2026-8071?
CVE-2026-8071 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-8071?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.