Custom fields frameworks render administrator-defined fields on post, term, user, and settings screens, store arbitrary meta, and expose AJAX endpoints for selecting posts, users, and terms, uploading and deleting files, and fetching oEmbeds. Meta Box – A Framework for Dynamic Websites version 5.15.1 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65699. The review focused on AJAX authorization and nonces, the file upload and delete flow, object-selection endpoints, meta storage and output escaping, and the [rwmb_meta] shortcode.
Plugin Security Certification (PSC-2026-65698): “Web Accessibility (formally known as Ally) – WCAG Scanning, Guided Fixes, Usability Widget” – Version 4.1.4

Accessibility widgets combine public front-end output with administrator-managed settings, on-page WCAG scanning, and guided fixes that change how content is presented to visitors. Web Accessibility (formally known as Ally) – WCAG Scanning, Guided Fixes, Usability Widget version 4.1.4 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65698. The review focused on REST API authorization, the public analytics endpoint, scan and remediation data handling, SVG icon uploads, and safe rendering of administrator-controlled widget settings.
Plugin Security Certification (PSC-2026-65697): “Child Theme Configurator” – Version 2.6.7

Child theme utilities inspect installed themes and can create or modify PHP, CSS, and configuration files inside the WordPress themes directory. Child Theme Configurator version 2.6.7 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65697. The review focused on administrative authorization, filesystem boundaries, theme and file selection, stylesheet parsing, template copying, and safe handling of configuration input.
Plugin Security Certification (PSC-2026-65696): “WP Mail Logging” – Version 1.16.0

Email logging plugins retain message bodies, recipient details, headers, attachments, and delivery errors that may contain sensitive operational data. WP Mail Logging version 1.16.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65696. The review focused on log access, stored message rendering, attachment references, search and bulk actions, resend requests, and protection of plugin settings.
Plugin Security Certification (PSC-2026-65695): “CookieAdmin – Cookie Consent Banner” – Version 1.2.3

Cookie consent tools combine public banner output with administrator-managed rules that determine when scripts and cookie groups can load. CookieAdmin – Cookie Consent Banner version 1.2.3 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65695. The review focused on protected configuration, consent state processing, script identification rules, cookie scan data, and safe rendering of visitor choices.
Force WordPress Users to Log Out with CleanTalk Shuffle Salts
CVE-2026-13245 – MaxButtons – Unauth Reflected XSS – POC

CVE-2026-13245 affects MaxButtons through version 9.8.5 and allows an unauthenticated attacker to inject an event handler into the admin list screen through the view query parameter. An administrator who opens a crafted URL and activates the injected access key can run JavaScript within their wp-admin session. This can expose administrative data or allow actions available to the victim account. The issue is fixed in version 9.8.6.
CVE-2025-15665 – BEAF – Admin+ Stored XSS – POC

CVE-2025-15665 affects the Ultimate Before After Image Slider & Gallery (BEAF) plugin and is an authenticated Admin+ Stored Cross-Site Scripting vulnerability in versions below 4.7.1. The BEAF Slider widget stores its Enter Shortcode value and passes it to do_shortcode() without escaping non-shortcode content, so an administrator or another trusted widget manager can persist markup that executes in the browser of any visitor who loads a page containing the widget. If an administrator views the affected page, the script runs in that authenticated origin and can become an account takeover path. The issue is fixed in version 4.7.1.
Disable PHP Execution in WordPress Uploads with CleanTalk
Plugin Security Certification (PSC-2026-64695): “Drag and Drop Multiple File Upload for Contact Form 7” – Version 1.4.0

File upload add-ons for Contact Form 7 receive untrusted files from anonymous website visitors, write them into the WordPress uploads directory, and expose AJAX endpoints for uploading and deleting those files. Drag and Drop Multiple File Upload for Contact Form 7 version 1.4.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64695, confirming that the review focused on unauthenticated AJAX upload handling, file-extension and MIME validation, filename sanitization and anti-script renaming, upload-path confinement, token-based file-deletion authorization, request rate limiting, and output escaping in the settings screen.

