nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-28221 CVE-2022-28221
MEDIUM
CleanTalk AntiSpam <= 5.173 Reflected XSS
Record summary
CVE-2022-28221 has a selected CVSS score of 6.1 (medium).
Description
The CleanTalk AntiSpam plugin <= 5.173 for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) via the $_REQUEST['page'] parameter in`/lib/Cleantalk/ApbctWP/FindSpam/ListTable/Comments.php`
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 7, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
CleanTalk AntiSpamBrowse CleanTalk / CleanTalk AntiSpam | CVE List | 5.173 to ≤ 5.173 | affected |
References
2wordfence.com
https://www.wordfence.com/blog/2022/03/reflected-xss-in-spam-protection-antispam-firewall-by-cleantalk