Plugin Security Certification (PSC-2026-64678): “Ninja Forms – The Contact Form Builder That Grows With You” – Version 3.14.11

Plugin Security Certification (PSC-2026-64678): “Ninja Forms – The Contact Form Builder That Grows With You” – Version 3.14.11

Form builders accept untrusted input from public visitors and turn it into stored records, notifications, and administrator workflows. Secure validation, permission checks, and careful output handling are central to every submission path. Ninja Forms – The Contact Form Builder That Grows With You version 3.14.11 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64678, confirming that the plugin was reviewed from a secure code perspective with attention to public submissions, field validation, stored form settings, administrator actions, notifications, and data exposure.

Plugin Security Certification (PSC-2026-64677): “Premium Addons for Elementor – Powerful Elementor Templates & Widgets” – Version 4.11.89

Plugin Security Certification (PSC-2026-64677): “Premium Addons for Elementor – Powerful Elementor Templates & Widgets” – Version 4.11.89

Elementor extension packs add widgets, templates, display rules, and dynamic output to the page builder. Because saved widget settings become public HTML, secure rendering and protected editor actions are essential. Premium Addons for Elementor – Powerful Elementor Templates & Widgets version 4.11.89 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64677, confirming that the plugin was reviewed from a secure code perspective with attention to widget configuration, template operations, dynamic rendering, editor requests, and stored front-end output.

Plugin Security Certification (PSC-2026-64676): “Smush – Image Optimization, Compression, Lazy Load, WebP & CDN” – Version 4.2.0

Plugin Security Certification (PSC-2026-64676): “Smush – Image Optimization, Compression, Lazy Load, WebP & CDN” – Version 4.2.0

Image optimization plugins process files that become part of nearly every public page. Compression, format conversion, lazy loading, and CDN delivery all need careful handling of uploads, metadata, and generated URLs. Smush – Image Optimization, Compression, Lazy Load, WebP & CDN version 4.2.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64676, confirming that the plugin was reviewed from a secure code perspective with attention to image processing inputs, media permissions, generated formats, remote delivery settings, and public markup.

Plugin Security Certification (PSC-2026-64675): “LiteSpeed Cache” – Version 7.8.1

Plugin Security Certification (PSC-2026-64675): “LiteSpeed Cache” – Version 7.8.1

Caching and optimization plugins sit directly in the path that produces a public page. Their settings can influence stored output, asset delivery, and the content returned to every visitor. LiteSpeed Cache version 7.8.1 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64675, confirming that the plugin was reviewed from a secure code perspective with attention to cache isolation, purge controls, generated assets, optimization requests, and privileged settings.

CVE-2025-13354 – TaxoPress – Missing Authorization – POC

CVE-2025-13354 – TaxoPress – Missing Authorization – POC

CVE-2025-13354 affects TaxoPress and allows authenticated Subscriber+ users to merge or delete arbitrary taxonomy terms through the taxopress_merge_terms_batch AJAX action. The handler validates a nonce that is available from profile.php but does not verify the taxonomy manage_terms capability. Its unbounded post lookup can also add significant load while terms are reassigned or removed.

CVE-2026-1673 – BEAR Bulk Editor – CSRF Term Deletion – POC

CVE-2026-1673 – BEAR Bulk Editor – CSRF Term Deletion – POC

CVE-2026-1673 affects BEAR Bulk Editor and Products Manager Professional for WooCommerce and is a cross site request forgery vulnerability that can delete WooCommerce taxonomy terms in versions through 1.1.5. The woobe_delete_tax_term AJAX action accepts tax_key and term_id without validating a WordPress nonce. An unauthenticated attacker can prepare a forged request that deletes product categories, tags, or other terms when a logged in administrator or shop manager visits a malicious page.