CVE-2025-15665 affects the Ultimate Before After Image Slider & Gallery (BEAF) plugin and is an authenticated Admin+ Stored Cross-Site Scripting vulnerability in versions below 4.7.1. The BEAF Slider widget stores its Enter Shortcode value and passes it to do_shortcode() without escaping non-shortcode content, so an administrator or another trusted widget manager can persist markup that executes in the browser of any visitor who loads a page containing the widget. If an administrator views the affected page, the script runs in that authenticated origin and can become an account takeover path. The issue is fixed in version 4.7.1.
Disable PHP Execution in WordPress Uploads with CleanTalk
Plugin Security Certification (PSC-2026-64695): “Drag and Drop Multiple File Upload for Contact Form 7” – Version 1.4.0

File upload add-ons for Contact Form 7 receive untrusted files from anonymous website visitors, write them into the WordPress uploads directory, and expose AJAX endpoints for uploading and deleting those files. Drag and Drop Multiple File Upload for Contact Form 7 version 1.4.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64695, confirming that the review focused on unauthenticated AJAX upload handling, file-extension and MIME validation, filename sanitization and anti-script renaming, upload-path confinement, token-based file-deletion authorization, request rate limiting, and output escaping in the settings screen.
CVE-2026-2381 – WooCommerce Stripe Gateway – Missing Authorization – POC

CVE-2026-2381 affects WooCommerce Stripe Payment Gateway and allows unauthenticated attackers to change pending orders to Failed through the public wc_stripe_pay_for_order endpoint. The handler accepts a supplied order ID without checking order ownership or an order key. A request with a fake payment method can trigger a payment error that changes the selected order status. Versions through 10.7.0 are affected, with a fix in 10.8.0.
CVE-2025-15693 – JCH Optimize – Path Traversal via the filetree dir Parameter – PoC
CVE-2025-15694 – Joli Table Of Contents – Stored XSS – PoC
CVE-2026-9134 – FooGallery – Contributor+ Stored XSS – POC

CVE-2026-9134 affects FooGallery and is an authenticated Contributor+ Stored Cross-Site Scripting vulnerability in versions up to and including 3.1.31. A crafted custom_attribute_key shortcode parameter can create an onmouseenter handler on the gallery container, causing persistent JavaScript to run when a visitor moves the pointer over the gallery. The issue is fixed in version 3.1.32.


