DIRAS TAKE
High priority: public comment submission can deliver the payload and it executes for anonymous visitors, so immediately reduce exposure by disabling the plugin or enforcing strict moderation and access controls until a vendor fix exists.
What is CVE-2026-77830?
Malicious actors can store JavaScript inside comments on sites using the Spam protection, Honeypot, Anti-Spam by CleanTalk WordPress plugin, leading to script execution in visitors’ browsers (CVE-2026-77830). The flaw affects the 6.x line through 6.86 and stems from inadequate filtering and escaping of comment-related input. An attacker able to create or submit comments can persist a payload; unauthenticated comment submission can deliver the payload and it runs when non-logged-in visitors view the page. If comments are moderated, a published comment is required before other users see it. The weakness is classified as CWE-79 (Cross-site Scripting).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Which versions of cleantalk Spam protection, Honeypot, Anti-Spam by CleanTalk are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 6.x | 6.86 and earlier |
Is CVE-2026-77830 being exploited?
There are no public reports of exploitation as of 2026-09-30.
How to fix CVE-2026-77830
- Disable or remove the CleanTalk Spam protection, Honeypot, Anti-Spam plugin until an official fix is released.
- Require manual approval for all comments and restrict commenting to authenticated users only.
- Use a web application firewall or edge rules to block or sanitize comment submission endpoints.
- Scan recent comments and web logs for injected scripts and remove any published malicious content immediately.
Frequently asked questions
Is CVE-2026-77830 being actively exploited?
There are no public reports of exploitation of CVE-2026-77830 as of 2026-09-30.
Which Spam protection, Honeypot, Anti-Spam by CleanTalk versions are affected by CVE-2026-77830?
Versions in the 6.x branch up to and including 6.86 are affected.
Is there a patch for CVE-2026-77830?
No patch is listed for CVE-2026-77830 as of 2026-09-30.
Does CVE-2026-77830 require authentication?
Creating the stored script requires an account with custom-level permissions or higher, but the payload can be submitted via unauthenticated comment submission and will execute for non-logged-in visitors; moderated comments must be published before other users see them.
References
- nvd.nist.gov/vuln/detail/CVE-2026-77830
- cve.org/CVERecord?id=CVE-2026-77830
- wordfence.com/threat-intel/vulnerabilities/id/10e7000b-597a-4165-8604-cb6b29714abb?source=cve
- plugins.trac.wordpress.org/browser/cleantalk-spam-protect/tags/6.85/lib/Cleantalk/Common/ContactsEncoder/ContactsEncoder.php#L914
- plugins.trac.wordpress.org/browser/cleantalk-spam-protect/tags/6.85/lib/Cleantalk/Common/ContactsEncoder/ContactsEncoder.php#L933
- plugins.trac.wordpress.org/browser/cleantalk-spam-protect/tags/6.85/lib/Cleantalk/ApbctWP/ContactsEncoder/ContactsEncoder.php#L114
- plugins.trac.wordpress.org/browser/cleantalk-spam-protect/tags/6.85/cleantalk.php#L234
- plugins.trac.wordpress.org/browser/cleantalk-spam-protect/tags/6.84/lib/Cleantalk/Common/ContactsEncoder/ContactsEncoder.php#L914
- plugins.trac.wordpress.org/browser/cleantalk-spam-protect/tags/6.84/lib/Cleantalk/Common/ContactsEncoder/ContactsEncoder.php#L933
- plugins.trac.wordpress.org/browser/cleantalk-spam-protect/tags/6.84/lib/Cleantalk/ApbctWP/ContactsEncoder/ContactsEncoder.php#L114
- plugins.trac.wordpress.org/browser/cleantalk-spam-protect/tags/6.84/cleantalk.php#L234
- plugins.trac.wordpress.org/changeset?reponame=&new=3677388%40cleantalk-spam-protect%2Ftags%2F6.87&old=3654120%40cleantalk-spam-protect%2Ftags%2F6.86
- plugins.trac.wordpress.org/changeset/3677388/cleantalk-spam-protect/trunk/lib/Cleantalk/Common/ContactsEncoder/ContactsEncoder.php
- plugins.trac.wordpress.org/changeset?old_path=%2Fcleantalk-spam-protect/tags/6.86&new_path=%2Fcleantalk-spam-protect/tags/6.87
- All cleantalk CVEs on CVE Radar
- CVEs published in September 2026