Plugin Security Certification (PSC-2026-64615): “BackUpWordPress” – Version 3.14

Plugin Security Certification (PSC-2026-64615): “BackUpWordPress” – Version 3.14

BackUpWordPress is a long-standing backup plugin originally created by Human Made and now maintained under new ownership with a continued commitment to open-source development. Designed for websites running on WordPress, the plugin provides scheduled backups of both files and databases using native system tools such as zip and mysqldump when available.

Its primary goal is simplicity: BackUpWordPress allows administrators to create full-site backups with minimal configuration, making it suitable even for low-memory shared hosting environments.

The plugin supports PHP 5.3.2+ and operates on both Linux and Windows servers, offering flexibility across hosting platforms.

Plugin Security Certification (PSC-2026-64612): “ReCaptcha v2 for Contact Form 7” – Version 1.4.9

Plugin Security Certification (PSC-2026-64612): “ReCaptcha v2 for Contact Form 7” – Version 1.4.9

ReCaptcha v2 for Contact Form 7 is a lightweight compatibility plugin designed to bring back Google reCAPTCHA v2 support to Contact Form 7 after version 5.1 removed the [recaptcha] tag in December 2018. Instead of introducing custom implementations or external wrappers, the plugin restores the original functionality from Contact Form 7 v5.0.5, preserving the familiar behavior many site owners relied on.

CVE-2026-2687 – Reading progressbar – Stored XSS – POC

CVE-2026-2687 – Reading progressbar – Stored XSS – POC

WordPress plugins that enhance user experience often expose administrative configuration fields that directly influence frontend rendering. When these fields are not properly sanitized, they can become a serious attack surface. CVE-2026-2687 affects the Reading Progressbar plugin, a lightweight tool that displays a reading progress indicator using an HTML5 element and JavaScript.

A stored Cross-Site Scripting (XSS) vulnerability was identified in the plugin’s settings panel, allowing an attacker to inject malicious JavaScript that is permanently stored and later executed in visitors’ or administrators’ browsers. This flaw can be leveraged to compromise administrator sessions, inject backdoors, or fully take over affected WordPress sites.

CVE-2025-10357 – Simple SEO – Stored XSS – POC

CVE-2025-10357 – Simple SEO – Stored XSS – POC

Simple SEO is a lightweight WordPress plugin that generates and manages SEO meta tags (title, meta description, keywords), supports quick-edit, sitemap generation and imports from other SEO plugins. In versions up to 2.0.32, the plugin contains a stored Cross-Site Scripting (XSS) vulnerability (CVE-2025-10357) that allows a user with Contributor (or higher) privileges to store malicious HTML/JS inside the plugin’s SEO fields (HTML-encoded Title). The injected script executes later when the field is rendered, potentially in the context of administrators or other privileged users.

Plugin Security Certification (PSC-2025-64597): “Redis Object Cache” – Version 2.7.0: Use Cache with Enhanced Security

Plugin Security Certification (PSC-2025-64597): “Redis Object Cache” – Version 2.7.0: Use Cache with Enhanced Security

Redis Object Cache 2.7.0 is a persistent object cache backend powered by Redis®¹, designed to enhance WordPress performance and scalability. It supports multiple PHP clients such as Predis, PhpRedis (PECL), and Relay, while offering advanced features like replication, sentinels, clustering, and seamless WP-CLI integration.

Plugin Security Certification (PSC-2025-64596): “PDF Embedder” – Version 4.9.2: Use PDF with Enhanced Security

Plugin Security Certification (PSC-2025-64596): “PDF Embedder” – Version 4.9.2: Use PDF with Enhanced Security

PDF Embedder is a powerful WordPress plugin that allows you to upload and embed PDF files directly into posts and pages, offering seamless document presentation with responsive design. Unlike other plugins that rely on iframes, PDF Embedder uses a unique JavaScript-based rendering method that gives site administrators complete control over the look, sizing, and navigation of embedded PDFs.

The plugin ensures that all PDF files and associated scripts are served from your own server, guaranteeing both faster performance and greater reliability, without reliance on third-party services. This approach enhances not only the user experience but also the security of your content.

The free version includes essential embedding functionality, while PDF Embedder Premium extends features with download options, hyperlink support, continuous scrolling, full-screen mode, and advanced mobile-friendly options.

Plugin Security Certification (PSC-2025-64593): “Meta pixel for WordPress” – Version 4.1.5: Use Logs with Enhanced Security

Plugin Security Certification (PSC-2025-64593): “Meta pixel for WordPress” – Version 4.1.5: Use Logs with Enhanced Security

WP Activity Log is a powerful WordPress plugin designed to provide detailed, real-time logging of all activities across your WordPress sites and multisite networks. From user login attempts to changes in posts, plugins, themes, and settings, this plugin gives administrators full visibility into everything that happens on their websites.

Plugin Security Certification (PSC-2025-64589): “WP Log Manager” – Version 5.5.4: Use Logs with Enhanced Security

Plugin Security Certification (PSC-2025-64589): “WP Log Manager” – Version 5.5.4: Use Logs with Enhanced Security

WP Activity Log is a powerful WordPress plugin designed to provide detailed, real-time logging of all activities across your WordPress sites and multisite networks. From user login attempts to changes in posts, plugins, themes, and settings, this plugin gives administrators full visibility into everything that happens on their websites.

With its granular event tracking, WP Activity Log helps site owners improve security, accountability, compliance, and troubleshooting. Administrators can detect suspicious activity before it escalates, meet compliance standards such as GDPR and PCI DSS, and streamline user management with accurate records of who did what, when, and from where.

By ensuring every action is logged, WP Activity Log provides a transparent and secure environment, making it a vital tool for businesses, agencies, and security professionals managing WordPress-powered sites.

Plugin Security Certification (PSC-2025-64587): “PHP Compatibility Cheker” – Version 1.6.3: Use Automatic Update WP with Enhanced Security

Plugin Security Certification (PSC-2025-64587): “PHP Compatibility Cheker” – Version 1.6.3: Use Automatic Update WP with Enhanced Security

PHP Compatibility Checker is a WordPress plugin developed by WP Engine that helps site administrators and developers analyze their WordPress themes and plugins for compatibility with modern PHP versions.

As WordPress continues to evolve, maintaining compatibility with supported PHP versions is a crucial factor for both performance and security. Outdated PHP releases no longer receive security updates, leaving websites at risk of vulnerabilities. This plugin empowers users to safely transition to newer PHP versions (up to PHP 8.0) by identifying errors and warnings in their installed codebase.

The tool uses linting technology combined with Tide’s scanning infrastructure to analyze plugin and theme files. It generates detailed reports with file names, line numbers, and descriptions of incompatibilities. Additionally, it recommends plugin or theme updates if newer versions include PHP compatibility fixes.

CVE-2025-9111 – WPBOT – Stored XSS – POC

CVE-2025-9111 – WPBOT – Stored XSS – POC

WPBot is a WordPress plugin that provides an AI-powered chatbot for websites, enabling live chat support, lead generation, and data collection. It integrates with OpenAI, ChatGPT, and other LLM services, while also offering built-in automated support without external AI dependencies.

A Stored Cross-Site Scripting (XSS) vulnerability was discovered in WPBot Lite that allows users to inject malicious scripts via the FAQ Builder, affecting users with sufficient access (such as contributors or admins reviewing FAQs). This vulnerability can lead to account compromise, data exfiltration, and site takeover.