Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 09 Sep 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The CleanTalk WordPress plugin before 6.87 does not prevent unauthenticated, user-supplied comment content from being passed to WordPress's shortcode engine, allowing any visitor to have arbitrary shortcodes registered on the site executed server-side and rendered to every subsequent visitor of the page. | |
| Title | Spam protection, Honeypot, Anti-Spam by CleanTalk < 6.87 - Unauthenticated Arbitrary Shortcode Execution via Comment Text | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-09T06:25:05.235Z
Reserved: 2026-08-14T09:43:54.757Z
Link: CVE-2026-19855
No data.
Status : Received
Published: 2026-09-09T07:16:56.500
Modified: 2026-09-09T07:16:56.500
Link: CVE-2026-19855
No data.
OpenCVE Enrichment
No data.
No weakness.
