CVE-2026-77830: stored cross-site scripting in cleantalk Spam protection, Honeypot, Anti-Spam by CleanTalk

Malicious actors can store JavaScript inside comments on sites using the Spam protection, Honeypot, Anti-Spam by CleanTalk WordPress plugin, leading to script execution in visitors’ browsers (CVE-2026-77830). The flaw affects the 6.x line through 6.86 and stems from inadequate filtering and escaping of comment-related input. An attacker able to create or submit comments can persist a payload; unauthenticated comment submission can deliver the payload and it runs when non-logged-in visitors view the page. If comments are moderated, a published comment is required before other users see it.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
7.2HIGH
EPSS
0.00474
CWE
CWE-79
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

High priority: public comment submission can deliver the payload and it executes for anonymous visitors, so immediately reduce exposure by disabling the plugin or enforcing strict moderation and access controls until a vendor fix exists.

What is CVE-2026-77830?

Malicious actors can store JavaScript inside comments on sites using the Spam protection, Honeypot, Anti-Spam by CleanTalk WordPress plugin, leading to script execution in visitors’ browsers (CVE-2026-77830). The flaw affects the 6.x line through 6.86 and stems from inadequate filtering and escaping of comment-related input. An attacker able to create or submit comments can persist a payload; unauthenticated comment submission can deliver the payload and it runs when non-logged-in visitors view the page. If comments are moderated, a published comment is required before other users see it. The weakness is classified as CWE-79 (Cross-site Scripting).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

Which versions of cleantalk Spam protection, Honeypot, Anti-Spam by CleanTalk are affected?

BRANCHAFFECTEDFIXED
6.x6.86 and earlier

Is CVE-2026-77830 being exploited?

There are no public reports of exploitation as of 2026-09-30.

How to fix CVE-2026-77830

  1. Disable or remove the CleanTalk Spam protection, Honeypot, Anti-Spam plugin until an official fix is released.
  2. Require manual approval for all comments and restrict commenting to authenticated users only.
  3. Use a web application firewall or edge rules to block or sanitize comment submission endpoints.
  4. Scan recent comments and web logs for injected scripts and remove any published malicious content immediately.

Frequently asked questions

Is CVE-2026-77830 being actively exploited?

There are no public reports of exploitation of CVE-2026-77830 as of 2026-09-30.

Which Spam protection, Honeypot, Anti-Spam by CleanTalk versions are affected by CVE-2026-77830?

Versions in the 6.x branch up to and including 6.86 are affected.

Is there a patch for CVE-2026-77830?

No patch is listed for CVE-2026-77830 as of 2026-09-30.

Does CVE-2026-77830 require authentication?

Creating the stored script requires an account with custom-level permissions or higher, but the payload can be submitted via unauthenticated comment submission and will execute for non-logged-in visitors; moderated comments must be published before other users see them.

References