CVE-2026-9125 affects Presto Player and is an authenticated Contributor+ Stored Cross-Site Scripting vulnerability in versions up to and including 4.2.0. A malicious presto_player_overlay shortcode can preserve a javascript: URI in link_url, allowing attacker-controlled JavaScript to run in the WordPress origin when another user clicks the overlay during playback.
SPBCT Critical Updates: Known CVEs and PSC Records
CVE-2026-7526 – PDF Embedder – Information Exposure – POC
CVE-2026-3985 – Creative Mail – Unauth SQL Injection – POC
CVE-2025-15345 – MapGeo – Unauth Reflected XSS – POC

CVE-2025-15345 affects MapGeo – Interactive Geo Maps and is an unauthenticated reflected Cross-Site Scripting vulnerability in versions up to and including 1.6.27. When a public page uses the display-map shortcode in demo mode, an attacker can supply an external JavaScript URL through the map parameter and make the victim browser load it under the vulnerable site context.
CVE-2026-6229 – Royal Addons for Elementor – Contributor+ SSRF – POC

CVE-2026-6229 affects Royal Addons for Elementor and is an authenticated Contributor+ server-side request forgery vulnerability in the Data Table widget. In versions through 1.7.1057, a user-controlled CSV URL can bypass the Google Sheets substring check, reach arbitrary internal or external HTTP services, and expose response data after it is parsed into the rendered table.
SC WordPress Malware in functions.php, db.php, and 1j2d192.php: Polymorphic Loaders and CleanTalk Cure
CVE-2025-11762 – HubSpot – Missing Authorization – POC
WP2Shell WordPress RCE Explained: CVE-2026-63030 and CVE-2026-60137
Plugin Security Certification (PSC-2026-64684): “CF7 Apps – Honeypot, Database, Redirection, Webhook, and Addons for Contact Form 7” – Version 3.6.1

Contact Form 7 extensions can influence spam checks, stored submissions, redirects, and outbound webhooks. These features cross the boundary between anonymous form input, privileged records, external destinations, and front-end responses. CF7 Apps – Honeypot, Database, Redirection, Webhook, and Addons for Contact Form 7 version 3.6.1 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64684, confirming that the plugin was reviewed from a secure code perspective with attention to public submissions, anti-spam checks, stored records, redirect targets, webhook configuration, and administrator access.


