The CVE-2026-77830 vulnerability in the Spam protection, Honeypot, Anti-Spam by CleanTalk plugin for WordPress allows authenticated attackers with custom-level access to inject arbitrary web scripts via comment content. The payload can be delivered through unauthenticated comment submission and executed for non-logged-in visitors. If comment moderation is enabled, a moderator must publish the comment befo [truncated]
CVE-2026-8071 is a HIGH-severity vulnerability in the Anti-Spam by CleanTalk. Spam protection WordPress plugin before version 6.79. The plugin does not properly sanitize content within a custom shortcode used in its email-encoding feature, allowing unauthenticated attackers to inject arbitrary web scripts into approved comments that will execute when any user (including administrators) views the post. The [truncated]