Caching and optimization plugins sit directly in the path that produces a public page. Their settings can influence stored output, asset delivery, and the content returned to every visitor. LiteSpeed Cache version 7.8.1 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64675, confirming that the plugin was reviewed from a secure code perspective with attention to cache isolation, purge controls, generated assets, optimization requests, and privileged settings.
CVE-2026-5428 – Royal Addons for Elementor – Stored XSS – POC

CVE-2026-5428 affects Royal Addons for Elementor and is an authenticated Author+ stored cross site scripting vulnerability in image captions rendered by the Image Grid, Slider, and Carousel widget. In versions through 1.7.1056, render_post_thumbnail() applies wp_kses_post() to data that is placed in an HTML attribute instead of using attribute-context escaping.
CVE-2026-5488 – ExactMetrics – Missing Authorization – POC

CVE-2026-5488 affects ExactMetrics and exposes Google Ads integration actions to authenticated Subscriber+ users. The get_ads_access_token() and reset_experience() AJAX handlers verify a nonce that is localized on profile.php but omit the exactmetrics_save_settings capability check. This can expose a live Google Ads access token or reset connected integration state.
CVE-2026-3885 – Shortcodes Ultimate – Stored XSS – POC

CVE-2026-3885 affects Shortcodes Ultimate and is an authenticated Contributor+ stored cross site scripting vulnerability in the su_box shortcode. In versions through 7.4.9, a crafted max_width value can break out of its HTML attribute and add an event handler. The stored browser code runs when a visitor interacts with the affected box.
CVE-2025-13354 – TaxoPress – Missing Authorization – POC

CVE-2025-13354 affects TaxoPress and allows authenticated Subscriber+ users to merge or delete arbitrary taxonomy terms through the taxopress_merge_terms_batch AJAX action. The handler validates a nonce that is available from profile.php but does not verify the taxonomy manage_terms capability. Its unbounded post lookup can also add significant load while terms are reassigned or removed.
Why Any Known Plugin CVE Now Costs 50 Safety Score Points
CVE-2026-1673 – BEAR Bulk Editor – CSRF Term Deletion – POC

CVE-2026-1673 affects BEAR Bulk Editor and Products Manager Professional for WooCommerce and is a cross site request forgery vulnerability that can delete WooCommerce taxonomy terms in versions through 1.1.5. The woobe_delete_tax_term AJAX action accepts tax_key and term_id without validating a WordPress nonce. An unauthenticated attacker can prepare a forged request that deletes product categories, tags, or other terms when a logged in administrator or shop manager visits a malicious page.
CVE-2026-1672 – BEAR Bulk Editor – CSRF to Product Update – POC

CVE-2026-1672 affects BEAR Bulk Editor and Products Manager Professional for WooCommerce and is a cross site request forgery vulnerability that can modify WooCommerce product data in versions through 1.1.5. The woobe_redraw_table_row AJAX action accepts product_id, field, and value without validating a WordPress nonce. An unauthenticated attacker can prepare a forged request that changes prices, descriptions, or other product fields when a logged in administrator or shop manager visits a malicious page.
CVE-2026-0738 – Shortcodes Ultimate – Stored XSS – POC

CVE-2026-0738 affects Shortcodes Ultimate and is an authenticated Author+ stored cross site scripting vulnerability in the su_carousel shortcode. In versions through 7.4.8, an unsafe value in the su_slide_link attachment field can be stored and rendered in carousel output. When a visitor moves the pointer over the affected slide link, browser code can run in that visitor’s session.
CVE-2026-0737 – Shortcodes Ultimate – Stored XSS – POC

CVE-2026-0737 affects Shortcodes Ultimate and is an authenticated Contributor+ stored cross site scripting vulnerability in the su_lightbox shortcode. In versions through 7.4.7, an attacker can store a crafted value in the shortcode src attribute. When a visitor activates the injected lightbox link, browser code can run in that visitor’s session.

