How to Find and Remove Malicious ELF Files on Your Website: CleanTalk’s BinaryCheck Module

How to Find and Remove Malicious ELF Files on Your Website: CleanTalk’s BinaryCheck Module

Most WordPress security scanners are good at catching malicious PHP code — web shells, injected theme and plugin files, suspicious eval() calls. But attackers have another tool in their arsenal: compiled binary files in ELF format (Executable and Linkable Format) — the standard executable format for Linux. Such a file contains no readable PHP code, doesn’t match familiar signatures found in plugin source files, and often has no file extension at all — so classic file scanners simply skip right past it.

This is exactly the gap that Security by CleanTalk’s new module — BinaryCheck — was built to close.

CVE-2025-15677 – GeoDirectory < 2.8.110 – Editor+ Stored XSS – POC

CVE-2025-15677 – GeoDirectory < 2.8.110 – Editor+ Stored XSS – POC

WordPress plugins that provide business directory functionality often allow administrators and editors to customize categories, icons, images, and other visual elements. While these features improve usability, they also increase the attack surface if user-controlled input is not properly validated before being stored and rendered.

During security testing of the GeoDirectory plugin, a Stored Cross-Site Scripting (Stored XSS) vulnerability was discovered affecting versions prior to 2.8.110. The vulnerability allows an authenticated Editor (or higher) to inject malicious JavaScript into the Map Icon parameter of a Place Category. The payload is permanently stored and later executed whenever the vulnerable page is viewed by another privileged user.

Because the malicious payload is stored inside the WordPress database, every administrator who accesses the affected interface can unknowingly execute attacker-controlled JavaScript, potentially resulting in complete administrative account compromise.

CVE-2025-15675 – Charitable < 1.8.5.3 – Admin+ Stored XSS – POC

CVE-2025-15675 – Charitable < 1.8.5.3 – Admin+ Stored XSS – POC

Charitable is a widely used WordPress donation and fundraising plugin that enables organizations to create fundraising campaigns, donation forms, recurring payment options, and crowdfunding initiatives. With its drag-and-drop campaign builder and customizable templates, it is trusted by thousands of nonprofits and charities to manage online donations.

During security testing, a Stored Cross-Site Scripting (XSS) vulnerability was identified in versions prior to 1.8.5.3. The vulnerability exists in the campaign builder, where the ALT Text field for campaign images fails to properly sanitize user input before storing and rendering it. As a result, an authenticated administrator can inject malicious JavaScript that is permanently stored and executed whenever the vulnerable content is rendered.

How Security by CleanTalk Protects WordPress Websites with Signature Analysis and Cloud Malware Detection

How Security by CleanTalk Protects WordPress Websites with Signature Analysis and Cloud Malware Detection

Every day, thousands of WordPress websites become targets for cybercriminals. Vulnerable plugins, outdated themes, weak passwords, and newly discovered security flaws allow attackers to upload malicious code, web shells, SEO spam, backdoors, and other dangerous files.

In many cases, website owners are completely unaware that their site has been compromised. Malware can remain active for weeks or even months while secretly redirecting visitors, sending spam, creating hidden administrator accounts, or providing attackers with full control over the server.

Plugin Security Certification (PSC-2026-64664): “Kadence Blocks — Page Builder Toolkit for Gutenberg Editor” – Version 4.1.9

Plugin Security Certification (PSC-2026-64664): “Kadence Blocks — Page Builder Toolkit for Gutenberg Editor” – Version 4.1.9

Kadence Blocks is a powerful extension for the native WordPress block editor, designed to provide advanced Gutenberg blocks, responsive layout controls, dynamic design tools, and professional website-building functionality without requiring custom code.

The plugin extends WordPress with a wide collection of custom blocks including Accordions, Advanced Buttons, Forms, Galleries, Tabs, Testimonials, Post Grids, Row Layouts, Progress Bars, Lottie Animations, and many more. It is optimized for performance, accessibility, and scalability while maintaining clean frontend output and modern design standards.

Plugin Security Certification (PSC-2026-64655): “Royal Addons for Elementor – Advanced Elementor Addons & Templates Kit Security Review” – Version 1.7.1062

Plugin Security Certification (PSC-2026-64655): “Royal Addons for Elementor – Advanced Elementor Addons & Templates Kit Security Review” – Version 1.7.1062

Royal Addons for Elementor – Addons and Templates Kit for Elementor is a comprehensive extension for the Elementor page builder, designed to help WordPress users create advanced websites without writing code. The plugin provides more than 100 Elementor widgets, 150+ template kits, WooCommerce builders, mega menu builders, AJAX search functionality, conditional visibility logic, popup builders, advanced filters, sliders, carousels, and many other frontend customization tools.

Plugin Security Certification (PSC-2026-64645): “Forminator Forms – Contact Form, Payment Form & Custom Form Builder” – Version 8.6.0

Plugin Security Certification (PSC-2026-64645): “Forminator Forms – Contact Form, Payment Form & Custom Form Builder” – Version 8.6.0

Forminator Forms – Contact Form, Payment Form & Custom Form Builder (v1.53.1) is a multifunctional WordPress plugin that enables the creation of forms, polls, quizzes, payment forms, and lead-generation tools through a drag-and-drop interface. It integrates with payment gateways, CRMs, and third-party services, making it a high-impact component in the application security surface.

Built for websites running on WordPress, Forminator handles sensitive user data, payments, file uploads, and AJAX interactions — making security a critical requirement.

The plugin functionality includes payments (Stripe, PayPal), quizzes, surveys, integrations, and GDPR-ready data handling

Plugin Security Certification (PSC-2026-64643): “Bug reporting tool & Website feedback. Spotfix” – Version 1.0.4

Plugin Security Certification (PSC-2026-64643): “Bug reporting tool & Website feedback. Spotfix” – Version 1.0.4

Bug reporting tool & Website feedback – Spotfix (v1.0.4) is a lightweight WordPress plugin that enables users to submit contextual feedback directly on website pages. By allowing visitors to highlight specific elements and attach comments (“Spots”), the plugin transforms feedback into structured, actionable tasks.

Designed for websites running on WordPress, Spotfix integrates frontend interaction with backend task management via external services, enabling teams to track and resolve issues efficiently.

Because the plugin processes user-generated content, interacts with external APIs, and injects frontend JavaScript widgets, a comprehensive security audit was conducted.