VYPR

Cleantalk Spam Protect

by WordPress

Source repositories

CVEs (4)

  • CVE-2023-33996HigDec 13, 2024
    risk 0.57cvss 8.8epss 0.01

    Missing Authorization vulnerability in СleanTalk - Anti-Spam Protection Spam protection, AntiSpam, FireWall by CleanTalk allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spam protection, AntiSpam, FireWall by CleanTalk: from n/a through…

  • CVE-2026-8071HigJun 10, 2026
    risk 0.50cvss 8.8epss 0.01

    The Anti-Spam by CleanTalk. Spam protection WordPress plugin before 6.79 does not properly sanitize content within a custom shortcode used in its email-encoding feature, allowing unauthenticated attackers to inject arbitrary web scripts into approved comments that will execute…

  • CVE-2026-19855MedSep 9, 2026
    risk 0.42cvss 6.5epss 0.00

    The CleanTalk WordPress plugin before 6.87 does not prevent unauthenticated, user-supplied comment content from being passed to WordPress's shortcode engine, allowing any visitor to have arbitrary shortcodes registered on the site executed server-side and rendered to every…

  • CVE-2019-17515MedNov 13, 2019
    risk 0.40cvss 6.1epss 0.01

    The CleanTalk cleantalk-spam-protect plugin before 5.127.4 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via the from or till parameter. The component is: inc/cleantalk-users.php and…