Plugin Security Certification (PSC-2025-64584): “Joinchat” – Version 6.0.6: Use Chat Integrations with Enhanced Security

Plugin Security Certification (PSC-2025-64584): “Joinchat” – Version 6.0.6: Use Chat Integrations with Enhanced Security

While its functionality is impressive, security remains a critical factor when embedding third-party scripts and handling visitor interactions. A vulnerable chat plugin could become a direct entry point for attackers—risking data leakage, phishing, and even complete site compromise. Recognizing this, Joinchat version 6.0.6 underwent an extensive Plugin Security Certification process by CleanTalk and has successfully earned PSC-2025-64584.

Plugin Security Certification (PSC-2025-64583): “String locator” – Version 2.6.7: Use Search locator with Enhanced Security

Plugin Security Certification (PSC-2025-64583): “String locator” – Version 2.6.7: Use Search locator with Enhanced Security

String Locator is a specialized WordPress plugin designed to help developers, administrators, and site managers quickly find and edit text strings within themes, plugins, and even WordPress core files. This tool eliminates the guesswork of locating hardcoded text by providing precise search results, including file paths, matching lines, and contextual previews.

The plugin also features in-browser editing, allowing you to make changes directly from the search results. Before saving, it runs a built-in consistency check that scans for unbalanced braces, brackets, and parentheses, reducing the risk of syntax errors and broken functionality. While not a substitute for full testing, this safeguard significantly minimizes common editing mistakes.

For maximum safety, it’s recommended to work on a staging site before deploying changes to production.

CVE-2025-6790 – Quiz And Survey Master (QSM) – Template Creation via CSRF – POC

CVE-2025-6790 – Quiz And Survey Master (QSM) – Template Creation via CSRF  – POC

Quiz And Survey Master (QSM) is a powerful WordPress plugin used to design and deploy quizzes, surveys, and assessments, with over 50,000 active installations. Despite its extensive use for educational and marketing purposes, a critical vulnerability—CVE-2025-6790—has been identified that permits unauthenticated attackers to perform Cross-Site Request Forgery (CSRF) against its AJAX endpoint for quiz template creation. This flaw allows an attacker to inject arbitrary templates into the system, potentially enabling further administrative actions or content hijacking without requiring any valid credentials.

Plugin Security Certification (PSC-2025-64582): “Everest Forms” – Version 3.4.0: Use Awesome Forms with Enhanced Security

Plugin Security Certification (PSC-2025-64582): “Everest Forms” – Version 3.4.0: Use Awesome Forms with Enhanced Security

Everest Forms has officially passed the Plugin Security Certification (PSC-2025-64582), issued by CleanTalk, following an exhaustive security audit. This validation affirms that Everest Forms is not only powerful in capability but also hardened against modern web threats, making it a safe solution for any WordPress website—personal, corporate, or eCommerce.

CVE-2025-8015 – Shortcodes Ultimate – Stored XSS (Author+) to Admin Account Creation – POC

CVE-2025-8015 – Shortcodes Ultimate – Stored XSS (Author+) to Admin Account Creation – POC

Shortcodes Ultimate is a ubiquitous WordPress plugin used by over 500,000 websites to effortlessly embed rich content—galleries, tabs, sliders—through simple shortcode syntax. While its drag-and-drop gallery builder and extensive shortcode library enhance user experience, a serious security flaw—CVE-2025-8015—has been discovered. This vulnerability permits an Author+ user to inject persistent JavaScript into gallery items (via image links or titles), which executes when administrators or other privileged users interact with the gallery. Ultimately, attackers can escalate privileges, create admin backdoors, and fully compromise the site.

CVE-2025-7369 – Shortcodes Ultimate – Unauthenticated Stored XSS via CSRF to Admin Account Creation – POC

CVE-2025-7369 – Shortcodes Ultimate – Unauthenticated Stored XSS via CSRF to Admin Account Creation – POC

The Shortcodes Ultimate plugin is a widely used WordPress toolkit, enabling site owners to add rich content elements—buttons, tabs, sliders—via simple shortcodes. With over 500,000 active installations, it is a go-to plugin for visual enhancements. However, a critical vulnerability, CVE-2025-7369, allows unauthenticated attackers to exploit a lack of CSRF protection on the plugin’s AJAX preview endpoint. By submitting a specially crafted form, an attacker can store malicious JavaScript in the database that executes in the administrator’s browser, opening the door to a full account-takeover backdoor.

Plugin Security Certification (PSC-2025-64581): “Performance Lab” – Version 3.9.0: Check Performance of your site with Enhanced Security

Plugin Security Certification (PSC-2025-64581): “Performance Lab” – Version 3.9.0: Check Performance of your site with Enhanced Security

As site speed and resource efficiency become vital factors in user experience and SEO, the Performance Lab plugin emerges as a strategic asset for WordPress site owners and developers. Built by the official WordPress Performance Team, this plugin acts as a modular testing ground for new performance-enhancing features that are expected to land in the WordPress core in the future.

Performance Lab has not only optimized web performance, but also achieved a significant security milestone by passing CleanTalk’s rigorous Plugin Security Certification process—PSC-2025-64581. This confirms the plugin’s readiness for production environments where performance and security must go hand in hand.

Plugin Security Certification (PSC-2025-64580): “AI Engine” – Version 2.9.9: Use AI with Enhanced Security

Plugin Security Certification (PSC-2025-64580): “AI Engine” – Version 2.9.9: Use AI with Enhanced Security

AI Engine is an advanced WordPress plugin designed to bridge the power of modern AI models (like GPT-4.1, Claude, Gemini, o4, and others) with the flexibility and usability of WordPress. Whether you’re aiming to build custom chatbots, generate content, translate articles, or automate content workflows, AI Engine provides a powerful and secure solution—all from within the WordPress dashboard.

With deep integrations, developer-ready APIs, and support for multiple AI providers, AI Engine allows website owners to build intelligent, interactive, and efficient websites that scale with their needs. Beyond just functionality, the plugin has undergone rigorous code-level inspection and has been certified with the Plugin Security Certification (PSC) from CleanTalk, confirming its secure development practices and strong protection measures.

Plugin Security Certification (PSC-2025-64579): “Custom Post Type UI” – Version 1.18.0: Custom Post Types with Enhanced Security

Plugin Security Certification (PSC-2025-64579): “Custom Post Type UI” – Version 1.18.0: Custom Post Types with Enhanced Security

Custom content structures are a cornerstone of advanced WordPress development. The Custom Post Type UI plugin empowers administrators and developers by offering a robust and user-friendly interface for registering and managing custom post types and taxonomies—without writing a single line of code.

Custom Post Type UI has successfully passed a comprehensive security audit and earned the Plugin Security Certification (PSC-2025-64579) from CleanTalk. This milestone confirms that the plugin adheres to the highest standards of secure coding practices, allowing users to leverage custom content types with confidence and protection.

From streamlining content architecture to enabling flexible taxonomies, CPTUI enhances WordPress functionality without compromising security.

Plugin Security Certification (PSC-2025-64578): “One Click Demo Import” – Version 3.3.0: Use Import Functionality with Enhanced Security

Plugin Security Certification (PSC-2025-64578): “One Click Demo Import” – Version 3.3.0: Use Import Functionality with Enhanced Security

When it comes to setting up WordPress themes, nothing is more frustrating for users than starting from scratch. The One Click Demo Import plugin solves this by offering a seamless, user-friendly method to load pre-built demo content with a single click. With version 3.3.0, the plugin continues to provide that convenience—now with an added layer of confidence: official Plugin Security Certification (PSC-2025-64578) from CleanTalk.