WP Activity Log is a powerful WordPress plugin designed to provide detailed, real-time logging of all activities across your WordPress sites and multisite networks. From user login attempts to changes in posts, plugins, themes, and settings, this plugin gives administrators full visibility into everything that happens on their websites.
Plugin Security Certification (PSC-2025-64592): “Redux Framework” – Version 4.5.7: Use Redux with Enhanced Security

The Redux Framework has long been the go-to options framework for WordPress developers. It provides an extensible, fully responsive environment for building option panels, customizer controls, and advanced UI fields for themes and plugins. By saving developers months of work, Redux accelerates innovation while maintaining a clean, standards-based architecture.
With the release of version 4.5.7, Redux Framework has officially achieved the Plugin Security Certification (PSC-2025-64592) by CleanTalk, confirming its resilience against critical web application vulnerabilities. This certification ensures that developers can integrate Redux into their projects with full confidence in both functionality and security hardening.
Plugin Security Certification (PSC-2025-64591): “GDPR Cookie Compliance” – Version 5.0.5: Use GDPR Compliance with Enhanced Security

Ensuring compliance with GDPR, CCPA, DSGVO, and other global privacy regulations is critical for every WordPress-powered website. The GDPR Cookie Compliance plugin (v5.0.5) provides an all-in-one solution for cookie consent management, offering flexibility, transparency, and full compliance with international data protection laws.
With its latest achievement, the plugin has been awarded the Plugin Security Certification (PSC-2025-64591) by CleanTalk, guaranteeing that its codebase is secure, hardened, and resilient against exploitation. This recognition reinforces the plugin’s position as one of the most trusted cookie compliance solutions for WordPress.
Plugin Security Certification (PSC-2025-64590): “UpdraftPlus” – Version 1.25.7: Use Backups with Enhanced Security

UpdraftPlus is the most trusted and widely used backup and migration plugin for WordPress, installed on more than 3 million websites worldwide. From simple scheduled backups to advanced migrations, it empowers site owners to protect and restore their WordPress environments with ease. With its extensive storage options—including Google Drive, Dropbox, Amazon S3, OneDrive, Azure, Backblaze, and more—UpdraftPlus provides unmatched flexibility.
Now, with its successful Plugin Security Certification (PSC-2025-64590) by CleanTalk, UpdraftPlus is officially recognized as not only the most feature-rich backup solution, but also as one of the most secure. This certification assures WordPress users that the plugin has undergone rigorous security audits to protect against a wide range of vulnerabilities.
Plugin Security Certification (PSC-2025-64589): “WP Log Manager” – Version 5.4.2: Use Logs with Enhanced Security

WP Activity Log is a powerful WordPress plugin designed to provide detailed, real-time logging of all activities across your WordPress sites and multisite networks. From user login attempts to changes in posts, plugins, themes, and settings, this plugin gives administrators full visibility into everything that happens on their websites.
With its granular event tracking, WP Activity Log helps site owners improve security, accountability, compliance, and troubleshooting. Administrators can detect suspicious activity before it escalates, meet compliance standards such as GDPR and PCI DSS, and streamline user management with accurate records of who did what, when, and from where.
By ensuring every action is logged, WP Activity Log provides a transparent and secure environment, making it a vital tool for businesses, agencies, and security professionals managing WordPress-powered sites.
Plugin Security Certification (PSC-2025-64588): “Superb Addons” – Version 3.6.1: Upgrade WordPress Editor with Enhanced Security

The Superb Addons plugin has quickly become one of the most popular solutions for enhancing the WordPress Gutenberg editor and other popular page builders. With its 10+ custom blocks, 200+ patterns, 50+ pre-built pages, animations, and a robust Theme Designer, it empowers website owners to create professional, responsive, and SEO-friendly websites without writing a single line of code.
Now, with its successful completion of the Plugin Security Certification (PSC-2025-64588) by CleanTalk, Superb Addons not only delivers cutting-edge features but also guarantees code-level security and reliability. This certification proves that the plugin has been rigorously tested against the most common and dangerous vulnerabilities in the WordPress ecosystem.
Plugin Security Certification (PSC-2025-64587): “PHP Compatibility Cheker” – Version 1.6.3: Use Automatic Update WP with Enhanced Security

PHP Compatibility Checker is a WordPress plugin developed by WP Engine that helps site administrators and developers analyze their WordPress themes and plugins for compatibility with modern PHP versions.
As WordPress continues to evolve, maintaining compatibility with supported PHP versions is a crucial factor for both performance and security. Outdated PHP releases no longer receive security updates, leaving websites at risk of vulnerabilities. This plugin empowers users to safely transition to newer PHP versions (up to PHP 8.0) by identifying errors and warnings in their installed codebase.
The tool uses linting technology combined with Tide’s scanning infrastructure to analyze plugin and theme files. It generates detailed reports with file names, line numbers, and descriptions of incompatibilities. Additionally, it recommends plugin or theme updates if newer versions include PHP compatibility fixes.
CVE-2025-9111 – WPBOT – Stored XSS – POC

WPBot is a WordPress plugin that provides an AI-powered chatbot for websites, enabling live chat support, lead generation, and data collection. It integrates with OpenAI, ChatGPT, and other LLM services, while also offering built-in automated support without external AI dependencies.
A Stored Cross-Site Scripting (XSS) vulnerability was discovered in WPBot Lite that allows users to inject malicious scripts via the FAQ Builder, affecting users with sufficient access (such as contributors or admins reviewing FAQs). This vulnerability can lead to account compromise, data exfiltration, and site takeover.
Plugin Security Certification (PSC-2025-64586): “WP Downgrade” – Version 1.2.6: Use Automatic Update WP with Enhanced Security

WP Downgrade | Specific Core Version is a vital WordPress plugin that allows administrators to downgrade or update their WordPress Core to a specific release. Unlike the default WordPress update routine, which only installs the latest release, this plugin provides flexible control over Core updates, enabling users to remain on a previous secure version or selectively update to compatible releases.
This is particularly useful for sites relying on plugins or themes that are not yet compatible with the latest WordPress release. By forcing WordPress to recognize a chosen version as the latest, WP Downgrade simplifies updates while maintaining compatibility and stability.
With the new advanced option, users can manually adjust the download link, enabling tasks like language-specific core downloads or fetching releases from alternative sources—all without compromising security.
CVE-2025-8891 – OceanWP [THEME] – Cross-Site Request Forgery to Ocean Extra Plugin Installation – POC
![CVE-2025-8891 – OceanWP [THEME] – Cross-Site Request Forgery to Ocean Extra Plugin Installation – POC CVE-2025-8891 – OceanWP [THEME] – Cross-Site Request Forgery to Ocean Extra Plugin Installation – POC](https://research.cleantalk.org/wp-content/uploads/2023/10/New_1_not_safe-1.png)
OceanWP is a widely adopted WordPress theme, boasting over 50,000 active installations thanks to its performance-optimized code and extensive customization options. To further extend its capabilities, it relies on a companion plugin, Ocean Extra, which adds demo import, custom widgets, and additional theme settings. However, a critical vulnerability—CVE-2025-8891—has been discovered: an unauthenticated Cross-Site Request Forgery (CSRF) flaw that allows any visitor to invoke the oceanwp_notice_button_click AJAX action. This function, when called, automatically installs or activates the Ocean Extra plugin, effectively granting low-privileged users the ability to install new code on the site without any consent or proper authorization checks.