CVE-2026-1430 – WP Lightbox 2 Stored XSS

CVE-2026-1430 – WP Lightbox 2 Stored XSS

WP Lightbox 2 is a WordPress plugin designed to add a responsive lightbox overlay effect to images displayed on a website. The plugin automatically enables lightbox functionality for images and galleries and provides several configuration options, including animation settings, overlay opacity, image information display, and additional descriptive text.

During security testing, a Stored Cross-Site Scripting (XSS) vulnerability was identified in the plugin’s settings panel. The issue allows malicious JavaScript to be injected through the “Additional text below image info” configuration field. Because this value is stored and later rendered on pages where the lightbox is used, the injected script may execute in the browsers of site visitors or administrators.

Plugin Security Certification (PSC-2026-64628): “Favicon by RealFaviconGenerator” – Version 1.3.45

Plugin Security Certification (PSC-2026-64628): “Favicon by RealFaviconGenerator” – Version 1.3.45

Favicon by RealFaviconGenerator (v1.3.45) is a WordPress plugin that automates the generation and deployment of platform-compatible favicons for desktop browsers, iOS devices, Android devices, Windows tablets, and more.

Modern favicon implementation requires multiple image sizes, platform-specific declarations, and compliance with different UI standards. This plugin simplifies the process by integrating WordPress with the RealFaviconGenerator service, generating all required assets in seconds.

Built for websites running on WordPress, the plugin eliminates manual favicon configuration while ensuring compatibility across browsers and operating systems.

Because the plugin interacts with an external generation service, performs file operations, and modifies theme headers, a structured security audit was conducted.

Plugin Security Certification (PSC-2026-64627): “All 404 Redirect to Homepage” – Version 5.5

Plugin Security Certification (PSC-2026-64627): “All 404 Redirect to Homepage” – Version 5.5

All 404 Redirect to Homepage (v5.5) is a WordPress plugin designed to automatically redirect 404 error pages to a specified destination using 301 SEO redirects. Instead of allowing visitors to encounter broken links, the plugin routes them to the homepage or a custom URL defined by the administrator.

Built for websites running on WordPress, the plugin focuses on improving SEO performance and user experience by minimizing exposure to 404 errors and preserving link equity.

However, because redirection logic directly affects HTTP responses and routing behavior, secure implementation is critical. Improper redirect handling can introduce open redirect vulnerabilities, redirect loops, or SEO manipulation vectors. Therefore, this plugin underwent a structured security audit.

Plugin Security Certification (PSC-2026-64626): “Instant Indexing for Google” – Version 1.1.22

Plugin Security Certification (PSC-2026-64626): “Instant Indexing for Google” – Version 1.1.22

Instant Indexing by Rank Math is a WordPress plugin that allows website owners to submit crawl requests to Google using the Google Indexing API immediately after publishing or updating content. Instead of waiting for standard search engine discovery cycles, the plugin automates indexing notifications directly from the WordPress dashboard.

Designed for websites running on WordPress, the plugin enables automated and manual submission of URLs to Google for faster crawling and indexing.

Google officially recommends the Indexing API primarily for Job Posting and Live Streaming websites. However, the plugin allows broader usage, and administrators should configure it responsibly.

Plugin Security Certification (PSC-2026-64615): “BackUpWordPress” – Version 3.14

Plugin Security Certification (PSC-2026-64615): “BackUpWordPress” – Version 3.14

BackUpWordPress is a long-standing backup plugin originally created by Human Made and now maintained under new ownership with a continued commitment to open-source development. Designed for websites running on WordPress, the plugin provides scheduled backups of both files and databases using native system tools such as zip and mysqldump when available.

Its primary goal is simplicity: BackUpWordPress allows administrators to create full-site backups with minimal configuration, making it suitable even for low-memory shared hosting environments.

The plugin supports PHP 5.3.2+ and operates on both Linux and Windows servers, offering flexibility across hosting platforms.

Plugin Security Certification (PSC-2026-64612): “ReCaptcha v2 for Contact Form 7” – Version 1.4.9

Plugin Security Certification (PSC-2026-64612): “ReCaptcha v2 for Contact Form 7” – Version 1.4.9

ReCaptcha v2 for Contact Form 7 is a lightweight compatibility plugin designed to bring back Google reCAPTCHA v2 support to Contact Form 7 after version 5.1 removed the [recaptcha] tag in December 2018. Instead of introducing custom implementations or external wrappers, the plugin restores the original functionality from Contact Form 7 v5.0.5, preserving the familiar behavior many site owners relied on.

CVE-2026-2687 – Reading progressbar – Stored XSS – POC

CVE-2026-2687 – Reading progressbar – Stored XSS – POC

WordPress plugins that enhance user experience often expose administrative configuration fields that directly influence frontend rendering. When these fields are not properly sanitized, they can become a serious attack surface. CVE-2026-2687 affects the Reading Progressbar plugin, a lightweight tool that displays a reading progress indicator using an HTML5 element and JavaScript.

A stored Cross-Site Scripting (XSS) vulnerability was identified in the plugin’s settings panel, allowing an attacker to inject malicious JavaScript that is permanently stored and later executed in visitors’ or administrators’ browsers. This flaw can be leveraged to compromise administrator sessions, inject backdoors, or fully take over affected WordPress sites.

CVE-2025-10357 – Simple SEO – Stored XSS – POC

CVE-2025-10357 – Simple SEO – Stored XSS – POC

Simple SEO is a lightweight WordPress plugin that generates and manages SEO meta tags (title, meta description, keywords), supports quick-edit, sitemap generation and imports from other SEO plugins. In versions up to 2.0.32, the plugin contains a stored Cross-Site Scripting (XSS) vulnerability (CVE-2025-10357) that allows a user with Contributor (or higher) privileges to store malicious HTML/JS inside the plugin’s SEO fields (HTML-encoded Title). The injected script executes later when the field is rendered, potentially in the context of administrators or other privileged users.

Plugin Security Certification (PSC-2025-64597): “Redis Object Cache” – Version 2.7.0: Use Cache with Enhanced Security

Plugin Security Certification (PSC-2025-64597): “Redis Object Cache” – Version 2.7.0: Use Cache with Enhanced Security

Redis Object Cache 2.7.0 is a persistent object cache backend powered by Redis®¹, designed to enhance WordPress performance and scalability. It supports multiple PHP clients such as Predis, PhpRedis (PECL), and Relay, while offering advanced features like replication, sentinels, clustering, and seamless WP-CLI integration.

Plugin Security Certification (PSC-2025-64596): “PDF Embedder” – Version 4.9.2: Use PDF with Enhanced Security

Plugin Security Certification (PSC-2025-64596): “PDF Embedder” – Version 4.9.2: Use PDF with Enhanced Security

PDF Embedder is a powerful WordPress plugin that allows you to upload and embed PDF files directly into posts and pages, offering seamless document presentation with responsive design. Unlike other plugins that rely on iframes, PDF Embedder uses a unique JavaScript-based rendering method that gives site administrators complete control over the look, sizing, and navigation of embedded PDFs.

The plugin ensures that all PDF files and associated scripts are served from your own server, guaranteeing both faster performance and greater reliability, without reliance on third-party services. This approach enhances not only the user experience but also the security of your content.

The free version includes essential embedding functionality, while PDF Embedder Premium extends features with download options, hyperlink support, continuous scrolling, full-screen mode, and advanced mobile-friendly options.