Plugin Security Certification (PSC-2026-64695): “Drag and Drop Multiple File Upload for Contact Form 7” – Version 1.4.0

Plugin Security Certification (PSC-2026-64695): “Drag and Drop Multiple File Upload for Contact Form 7” – Version 1.4.0

File upload add-ons for Contact Form 7 receive untrusted files from anonymous website visitors, write them into the WordPress uploads directory, and expose AJAX endpoints for uploading and deleting those files. Drag and Drop Multiple File Upload for Contact Form 7 version 1.4.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64695, confirming that the review focused on unauthenticated AJAX upload handling, file-extension and MIME validation, filename sanitization and anti-script renaming, upload-path confinement, token-based file-deletion authorization, request rate limiting, and output escaping in the settings screen.

CVE-2026-2381 – WooCommerce Stripe Gateway – Missing Authorization – POC

CVE-2026-2381 – WooCommerce Stripe Gateway – Missing Authorization – POC

CVE-2026-2381 affects WooCommerce Stripe Payment Gateway and allows unauthenticated attackers to change pending orders to Failed through the public wc_stripe_pay_for_order endpoint. The handler accepts a supplied order ID without checking order ownership or an order key. A request with a fake payment method can trigger a payment error that changes the selected order status. Versions through 10.7.0 are affected, with a fix in 10.8.0.

CVE-2026-9134 – FooGallery – Contributor+ Stored XSS – POC

CVE-2026-9134 – FooGallery – Contributor+ Stored XSS – POC

CVE-2026-9134 affects FooGallery and is an authenticated Contributor+ Stored Cross-Site Scripting vulnerability in versions up to and including 3.1.31. A crafted custom_attribute_key shortcode parameter can create an onmouseenter handler on the gallery container, causing persistent JavaScript to run when a visitor moves the pointer over the gallery. The issue is fixed in version 3.1.32.

Plugin Security Certification (PSC-2026-64694): “Force Regenerate Thumbnails” – Version 2.3.0

Plugin Security Certification (PSC-2026-64694): “Force Regenerate Thumbnails” – Version 2.3.0

Thumbnail regeneration tools delete derived image sizes, read original uploads, create replacement files, and execute batch operations across the media library. Force Regenerate Thumbnails version 2.3.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64694, confirming that the review focused on attachment authorization, path confinement, batch requests, file deletion scope, image processing inputs, and progress handling.

Plugin Security Certification (PSC-2026-64693): “Advanced Google reCAPTCHA” – Version 5.40

Plugin Security Certification (PSC-2026-64693): “Advanced Google reCAPTCHA” – Version 5.40

CAPTCHA integrations sit on public login, registration, password reset, comment, commerce, and community forms where untrusted requests meet account and content workflows. Advanced Google reCAPTCHA version 5.40 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64693, confirming that the review focused on token verification, protected form coverage, settings authorization, remote API handling, bypass resistance, and safe failure behavior.