CVE-2022-28221: CleanTalk AntiSpam <= 5.173 Reflected XSS
The CleanTalk AntiSpam plugin <= 5.173 for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) via the $REQUEST['page'] parameter in/lib/Cleantalk/ApbctWP/FindSpam/ListTable/Comments.php
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-28221?
CVE-2022-28221 is a vulnerability in the CleanTalk AntiSpam plugin for WordPress that allows for Reflected Cross-Site Scripting (XSS) attacks.
How does CVE-2022-28221 affect CleanTalk AntiSpam plugin?
CVE-2022-28221 affects the CleanTalk AntiSpam plugin version 5.173 and earlier, allowing attackers to perform XSS attacks through the '$_REQUEST['page']' parameter in '/lib/Cleantalk/ApbctWP/FindSpam/ListTable/Comments.php'.
What is the severity of CVE-2022-28221?
CVE-2022-28221 has a severity rating of 6.1 (Medium).
How can I fix the CVE-2022-28221 vulnerability?
To fix the CVE-2022-28221 vulnerability, you should update the CleanTalk AntiSpam plugin to the latest version available, which is not affected by this vulnerability.
Where can I find more information about CVE-2022-28221?
You can find more information about CVE-2022-28221 on the Wordfence blog: [Wordfence Blog - Reflected XSS in Spam Protection Antispam Firewall by CleanTalk](https://www.wordfence.com/blog/2022/03/reflected-xss-in-spam-protection-antispam-firewall-by-cleantalk/)