Multilingual plugins store translated text and insert it into front-end output across themes and other plugins. Visual editing, language routing, and automatic translation features require firm access controls and consistent escaping. TranslatePress – Translate Multilingual sites with AI Translation version 3.2.6 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64679, confirming that the plugin was reviewed from a secure code perspective with attention to translation storage, visual editor permissions, multilingual routing, automatic translation settings, and public output.
Plugin Security Certification (PSC-2026-64678): “Ninja Forms – The Contact Form Builder That Grows With You” – Version 3.14.11

Form builders accept untrusted input from public visitors and turn it into stored records, notifications, and administrator workflows. Secure validation, permission checks, and careful output handling are central to every submission path. Ninja Forms – The Contact Form Builder That Grows With You version 3.14.11 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64678, confirming that the plugin was reviewed from a secure code perspective with attention to public submissions, field validation, stored form settings, administrator actions, notifications, and data exposure.
Plugin Security Certification (PSC-2026-64677): “Premium Addons for Elementor – Powerful Elementor Templates & Widgets” – Version 4.11.89

Elementor extension packs add widgets, templates, display rules, and dynamic output to the page builder. Because saved widget settings become public HTML, secure rendering and protected editor actions are essential. Premium Addons for Elementor – Powerful Elementor Templates & Widgets version 4.11.89 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64677, confirming that the plugin was reviewed from a secure code perspective with attention to widget configuration, template operations, dynamic rendering, editor requests, and stored front-end output.
Plugin Security Certification (PSC-2026-64676): “Smush – Image Optimization, Compression, Lazy Load, WebP & CDN” – Version 4.2.0

Image optimization plugins process files that become part of nearly every public page. Compression, format conversion, lazy loading, and CDN delivery all need careful handling of uploads, metadata, and generated URLs. Smush – Image Optimization, Compression, Lazy Load, WebP & CDN version 4.2.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64676, confirming that the plugin was reviewed from a secure code perspective with attention to image processing inputs, media permissions, generated formats, remote delivery settings, and public markup.
Plugin Security Certification (PSC-2026-64675): “LiteSpeed Cache” – Version 7.8.1

Caching and optimization plugins sit directly in the path that produces a public page. Their settings can influence stored output, asset delivery, and the content returned to every visitor. LiteSpeed Cache version 7.8.1 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64675, confirming that the plugin was reviewed from a secure code perspective with attention to cache isolation, purge controls, generated assets, optimization requests, and privileged settings.
CVE-2026-5428 – Royal Addons for Elementor – Stored XSS – POC

CVE-2026-5428 affects Royal Addons for Elementor and is an authenticated Author+ stored cross site scripting vulnerability in image captions rendered by the Image Grid, Slider, and Carousel widget. In versions through 1.7.1056, render_post_thumbnail() applies wp_kses_post() to data that is placed in an HTML attribute instead of using attribute-context escaping.
CVE-2026-5488 – ExactMetrics – Missing Authorization – POC

CVE-2026-5488 affects ExactMetrics and exposes Google Ads integration actions to authenticated Subscriber+ users. The get_ads_access_token() and reset_experience() AJAX handlers verify a nonce that is localized on profile.php but omit the exactmetrics_save_settings capability check. This can expose a live Google Ads access token or reset connected integration state.
CVE-2026-3885 – Shortcodes Ultimate – Stored XSS – POC

CVE-2026-3885 affects Shortcodes Ultimate and is an authenticated Contributor+ stored cross site scripting vulnerability in the su_box shortcode. In versions through 7.4.9, a crafted max_width value can break out of its HTML attribute and add an event handler. The stored browser code runs when a visitor interacts with the affected box.
CVE-2025-13354 – TaxoPress – Missing Authorization – POC

CVE-2025-13354 affects TaxoPress and allows authenticated Subscriber+ users to merge or delete arbitrary taxonomy terms through the taxopress_merge_terms_batch AJAX action. The handler validates a nonce that is available from profile.php but does not verify the taxonomy manage_terms capability. Its unbounded post lookup can also add significant load while terms are reassigned or removed.
