Plugin Security Certification (PSC-2026-64658): “FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider” – Version 2.2.95

Plugin Security Certification (PSC-2026-64658): “FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider” – Version 2.2.95

SMTP and email routing plugins hold highly sensitive operational data because they connect WordPress to external mail infrastructure, API credentials, OAuth-based providers, email logs, and resend workflows. Weak controls in this layer can expose tokens, disclose private email content, alter transactional mail routing, or allow unauthorized users to resend messages. FluentSMTP version 2.2.95 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64658, confirming that the plugin was reviewed from a secure code perspective with attention to common exploitation paths for mail delivery and email logging plugins.

Plugin Security Certification (PSC-2026-64659): “Meta for WooCommerce” – Version 3.7.0

Plugin Security Certification (PSC-2026-64659): “Meta for WooCommerce” – Version 3.7.0

Commerce integrations expand a WordPress site beyond local content management into external advertising, catalog synchronization, tracking pixels, conversion APIs, and customer communication channels. That integration layer is powerful, but it also increases exposure around tokens, product metadata, order-related events, tracking configuration, and administrator onboarding flows. Meta for WooCommerce version 3.7.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64659, confirming that the plugin was reviewed from a secure code perspective with attention to common exploitation paths for WooCommerce marketing and platform-integration plugins.

Plugin Security Certification (PSC-2026-64660): “Custom Fonts – Host Your Fonts Locally” – Version 2.1.17

Plugin Security Certification (PSC-2026-64660): “Custom Fonts – Host Your Fonts Locally” – Version 2.1.17

Typography plugins appear presentation-oriented, but their core workflows involve file uploads, local asset hosting, generated CSS, editor integration, and front-end output. That combination can become security-sensitive when font files, font names, CSS rules, and generated asset paths are accepted from administrators or imported from external providers. Custom Fonts version 2.1.17 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64660, confirming that the plugin was reviewed from a secure code perspective with attention to common exploitation paths for local font hosting and typography customization plugins.

Plugin Security Certification (PSC-2026-64656): “Click to Chat – HoliThemes” – Version 4.39

Plugin Security Certification (PSC-2026-64656): “Click to Chat – HoliThemes” – Version 4.39

WhatsApp contact widgets are small from a user-experience perspective, but they sit on a sensitive boundary between public visitors, business communication flows, tracking, shortcodes, and administrator-controlled display rules. A misstep in this layer can turn a support button into a stored XSS vector, an unsafe redirect path, or a leakage point for contact and form data. Click to Chat – HoliThemes version 4.39 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64656, confirming that the plugin was reviewed from a secure code perspective with attention to common exploitation paths for communication and front-end widget plugins.

Plugin Security Certification (PSC-2026-64657): “SiteGuard WP Plugin” – Version 1.7.12

Plugin Security Certification (PSC-2026-64657): “SiteGuard WP Plugin” – Version 1.7.12

Login hardening plugins operate directly on WordPress authentication, administration access, CAPTCHA behavior, lockout logic, and security notifications. That position gives them defensive value, but it also creates a high-impact attack surface: weak validation or unsafe configuration handling can cause lockout bypass, administrator denial of service, sensitive path disclosure, or unauthorized modification of protection rules. SiteGuard WP Plugin version 1.7.12 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64657, confirming that the plugin was reviewed from a secure code perspective with attention to common exploitation paths for login protection and administrative security plugins.

Plugin Security Certification (PSC-2026-64655): “Royal Addons for Elementor – Advanced Elementor Addons & Templates Kit Security Review” – Version 1.7.1062

Plugin Security Certification (PSC-2026-64655): “Royal Addons for Elementor – Advanced Elementor Addons & Templates Kit Security Review” – Version 1.7.1062

Royal Addons for Elementor – Addons and Templates Kit for Elementor is a comprehensive extension for the Elementor page builder, designed to help WordPress users create advanced websites without writing code. The plugin provides more than 100 Elementor widgets, 150+ template kits, WooCommerce builders, mega menu builders, AJAX search functionality, conditional visibility logic, popup builders, advanced filters, sliders, carousels, and many other frontend customization tools.

CVE-2025-13048 – Official StatCounter Plugin – Stored XSS to Contributor+ Persistent Script Execution – POC

CVE-2025-13048 – Official StatCounter Plugin – Stored XSS to Contributor+ Persistent Script Execution – POC

CVE-2025-13048 affects Official StatCounter Plugin and it is an authenticated Stored Cross-Site Scripting vulnerability that allows a Contributor or higher user to store a crafted payload in the WordPress Nickname field. The vulnerability is triggered when the affected post is viewed and the plugin renders the author nickname into a JavaScript context without proper sanitization and escaping. The practical security outcome is persistent browser side code execution against visitors and administrators who open the injected post. On real sites this can lead to session theft, unauthorized admin actions, malicious redirects, or further compromise of the WordPress dashboard.

CVE-2026-2515 – Hostinger Reach – Missing Authorization to Authenticated (Subscriber+) Integration API Key Update – POC

CVE-2026-2515 – Hostinger Reach – Missing Authorization to Authenticated (Subscriber+) Integration API Key Update – POC

CVE-2026-2515 affects Hostinger Reach and it is a missing authorization vulnerability that allows a low privilege authenticated user to trigger an admin only site connection flow and ultimately overwrite the persistent Reach bearer credential stored in WordPress options. The practical security outcome is not a minor UI glitch. It is third party integration takeover. A Subscriber can rebind the WordPress site to an attacker controlled Reach tenant, disrupt the legitimate integration, and potentially divert marketing data and automation feeds. On sites where WooCommerce related automation is enabled, the downstream impact can extend to billing and order PII flowing into the attacker account because the plugin believes it is still connected to the correct Reach backend.

CVE-2026-5371 – MonsterInsights – Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure And Plugin Integration Reset – POC

CVE-2026-5371 – MonsterInsights – Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure And Plugin Integration Reset – POC

CVE-2026-5371 affects MonsterInsights and it is a missing authorization vulnerability that turns a low privilege WordPress account into a bridge for cross platform credential theft. The issue is not limited to reading plugin settings. It allows a Subscriber to obtain a live Google OAuth access token that was granted during the site owner’s Google onboarding flow, and it also allows the same low privilege user to reset the Google Ads integration state. That combination creates both confidentiality and integrity impact. The token is a portable bearer credential which means it can be used outside WordPress against Google APIs until it expires or is revoked. With a reported install base above two million, the exposure is significant because many sites have public registration and routinely have low privilege accounts that are easy to obtain.