File upload add-ons for Contact Form 7 receive untrusted files from anonymous website visitors, write them into the WordPress uploads directory, and expose AJAX endpoints for uploading and deleting those files. Drag and Drop Multiple File Upload for Contact Form 7 version 1.4.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64695, confirming that the review focused on unauthenticated AJAX upload handling, file-extension and MIME validation, filename sanitization and anti-script renaming, upload-path confinement, token-based file-deletion authorization, request rate limiting, and output escaping in the settings screen.
CVE-2026-2381 – WooCommerce Stripe Gateway – Missing Authorization – POC

CVE-2026-2381 affects WooCommerce Stripe Payment Gateway and allows unauthenticated attackers to change pending orders to Failed through the public wc_stripe_pay_for_order endpoint. The handler accepts a supplied order ID without checking order ownership or an order key. A request with a fake payment method can trigger a payment error that changes the selected order status. Versions through 10.7.0 are affected, with a fix in 10.8.0.
CVE-2025-15693 – JCH Optimize – Path Traversal via the filetree dir Parameter – PoC
CVE-2025-15694 – Joli Table Of Contents – Stored XSS – PoC
CVE-2026-9134 – FooGallery – Contributor+ Stored XSS – POC

CVE-2026-9134 affects FooGallery and is an authenticated Contributor+ Stored Cross-Site Scripting vulnerability in versions up to and including 3.1.31. A crafted custom_attribute_key shortcode parameter can create an onmouseenter handler on the gallery container, causing persistent JavaScript to run when a visitor moves the pointer over the gallery. The issue is fixed in version 3.1.32.
CVE-2025-15663 – Ultimate Before After Image Slider & Gallery (BEAF) – Author+ Stored XSS via After Label – PoC
WordPress Firewall Plugin: How to Block IPs, Countries and Bot Floods with Security by CleanTalk
Two-Factor Authentication for WordPress: Why 2FA Matters and How to Enable It
Plugin Security Certification (PSC-2026-64694): “Force Regenerate Thumbnails” – Version 2.3.0

Thumbnail regeneration tools delete derived image sizes, read original uploads, create replacement files, and execute batch operations across the media library. Force Regenerate Thumbnails version 2.3.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64694, confirming that the review focused on attachment authorization, path confinement, batch requests, file deletion scope, image processing inputs, and progress handling.
Plugin Security Certification (PSC-2026-64693): “Advanced Google reCAPTCHA” – Version 5.40

CAPTCHA integrations sit on public login, registration, password reset, comment, commerce, and community forms where untrusted requests meet account and content workflows. Advanced Google reCAPTCHA version 5.40 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64693, confirming that the review focused on token verification, protected form coverage, settings authorization, remote API handling, bypass resistance, and safe failure behavior.

