CVE-2026-8071
EUVD-2026-3598610.06.2026, 07:16
The Anti-Spam by CleanTalk. Spam protection WordPress plugin before 6.79 does not properly sanitize content within a custom shortcode used in its email-encoding feature, allowing unauthenticated attackers to inject arbitrary web scripts into approved comments that will execute when any user (including administrators) views the post.
Awaiting analysis
This vulnerability is currently awaiting analysis.