{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/spam-protection-honeypot-anti-spam-by-cleantalk--6.86/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:cleantalk:spam_protection_honeypot_anti_spam_by_cleantalk:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-77830"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Spam protection, Honeypot, Anti-Spam by CleanTalk (\u003c= 6.86)"],"_cs_severities":["high"],"_cs_tags":["xss","web-vulnerability","wordpress"],"_cs_type":"advisory","_cs_vendors":["CleanTalk"],"content_html":"\u003cp\u003eThe Spam protection, Honeypot, Anti-Spam by CleanTalk plugin for WordPress is vulnerable to stored cross-site scripting (XSS) in all versions up to and including 6.86. The vulnerability stems from insufficient sanitization of input data when processing the comment content aria-label placeholder. Authenticated attackers with custom-level access or higher can inject arbitrary JavaScript payloads through comment submissions. If comment moderation is enabled on the WordPress installation, the payload remains dormant until a site administrator approves the comment. Once published, the malicious script executes within the browser context of any non-logged-in visitor who views the page containing the comment. This vulnerability represents a significant risk for site integrity, potentially allowing for session hijacking, malicious redirects, or unauthorized actions performed on behalf of the victim.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in arbitrary code execution within the context of site visitors' browsers. This can lead to the theft of session cookies, redirection to malicious phishing sites, or unauthorized modifications to the page content viewed by the end-user. The target audience for the malicious script is primarily non-authenticated visitors, though the scope of impact depends on the traffic volume and the visibility of the compromised comment section on the affected WordPress site.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for detection engineering and security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the \u0026quot;Spam protection, Honeypot, Anti-Spam by CleanTalk\u0026quot; plugin to version 6.87 or the latest available release to resolve the sanitization flaw identified in CVE-2026-77830.\u003c/li\u003e\n\u003cli\u003eReview web access logs for suspicious HTTP POST requests directed at the WordPress comment submission endpoint (typically /wp-comments-post.php) that contain script tags or suspicious JavaScript event handlers in the comment metadata.\u003c/li\u003e\n\u003cli\u003eEnforce strict content security policies (CSP) on WordPress deployments to mitigate the execution of unauthorized inline scripts.\u003c/li\u003e\n\u003cli\u003eAudit user roles and permissions to ensure that only trusted users possess custom-level or higher access to the WordPress environment.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-05T07:30:46Z","date_published":"2026-09-05T07:30:46Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cleantalk-xss/","summary":"The Spam protection, Honeypot, Anti-Spam by CleanTalk plugin for WordPress is vulnerable to stored cross-site scripting via insufficient input sanitization in the comment content aria-label placeholder, allowing attackers to execute arbitrary scripts in the browsers of site visitors.","title":"Stored XSS in CleanTalk WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-cleantalk-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Spam Protection, Honeypot, Anti-Spam by CleanTalk (\u003c= 6.86)","version":"https://jsonfeed.org/version/1.1"}