CVE-2026-2381 affects WooCommerce Stripe Payment Gateway and allows unauthenticated attackers to change pending orders to Failed through the public wc_stripe_pay_for_order endpoint. The handler accepts a supplied order ID without checking order ownership or an order key. A request with a fake payment method can trigger a payment error that changes the selected order status. Versions through 10.7.0 are affected, with a fix in 10.8.0.
CVE-2025-15693 – JCH Optimize – Path Traversal via the filetree dir Parameter – PoC
CVE-2025-15694 – Joli Table Of Contents – Stored XSS – PoC
CVE-2026-9134 – FooGallery – Contributor+ Stored XSS – POC

CVE-2026-9134 affects FooGallery and is an authenticated Contributor+ Stored Cross-Site Scripting vulnerability in versions up to and including 3.1.31. A crafted custom_attribute_key shortcode parameter can create an onmouseenter handler on the gallery container, causing persistent JavaScript to run when a visitor moves the pointer over the gallery. The issue is fixed in version 3.1.32.
CVE-2025-15663 – Ultimate Before After Image Slider & Gallery (BEAF) – Author+ Stored XSS via After Label – PoC
WordPress Firewall Plugin: How to Block IPs, Countries and Bot Floods with Security by CleanTalk
Two-Factor Authentication for WordPress: Why 2FA Matters and How to Enable It
Plugin Security Certification (PSC-2026-64694): “Force Regenerate Thumbnails” – Version 2.3.0

Thumbnail regeneration tools delete derived image sizes, read original uploads, create replacement files, and execute batch operations across the media library. Force Regenerate Thumbnails version 2.3.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64694, confirming that the review focused on attachment authorization, path confinement, batch requests, file deletion scope, image processing inputs, and progress handling.
Plugin Security Certification (PSC-2026-64693): “Advanced Google reCAPTCHA” – Version 5.40

CAPTCHA integrations sit on public login, registration, password reset, comment, commerce, and community forms where untrusted requests meet account and content workflows. Advanced Google reCAPTCHA version 5.40 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64693, confirming that the review focused on token verification, protected form coverage, settings authorization, remote API handling, bypass resistance, and safe failure behavior.
Plugin Security Certification (PSC-2026-64692): “Health Check & Troubleshooting” – Version 1.7.1

Diagnostic plugins inspect server and WordPress configuration, collect debug data, verify files and email delivery, and alter plugin or theme state for a troubleshooting session. Health Check & Troubleshooting version 1.7.1 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64692, confirming that the review focused on privileged diagnostics, session isolation, debug data disclosure, file integrity checks, tool requests, and temporary troubleshooting controls.

