cleantalk

Vulnerabilities and Security Researches

Recent vulnerability researches

CVE/PSC Application Date Affected versions Description
Actual on: Aug 18, 2026, 18:08:30

CVE-2026-66667

Templately – Gutenberg & Elementor Template Library: 5000+ Free & Pro Ready Templates & Cloud!

vulnerable

Aug 18, 2026, 22:08:38
Min -
Max 3.7.2
Unauthenticated Cross Site Scripting (XSS) in Templately <= 3.7.1 versions.

CVE-2026-75091

Quill Forms | The Best Typeform Alternative | Create Conversational Multi Step Form, Survey, Quiz, Cost Estimation or Donation

vulnerable

Aug 18, 2026, 19:08:47
Min -
Max 5.7.1
The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2026-73995

User Registration &#8211; Custom Registration Form, Login Form, and User Profile WordPress Plugin

vulnerable

Aug 18, 2026, 18:08:53
Min -
Max 5.2.7
User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 5.2.7 CVE-2026-73995

CVE-2026-14498

Query Wrangler

vulnerable

Aug 18, 2026, 14:08:36
Min -
Max 1.5.58
The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5.57 via the 'options' parameter parameter. This is due to missing capability check and nonce verification on the wp_ajax_qw_form_ajax handler, combined with unsanitized attacker-controlled options fully replacing saved query options and being passed directly to call_user_func_array() guarded only by function_exists(). This makes it possible for authenticated attackers, with subscriber-leve...

CVE-2026-14524

ProSolution WP Client

vulnerable

Aug 18, 2026, 14:08:23
Min -
Max 2.0.9
The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the proSol_fileDeleteProcess function in all versions up to, and including, 2.0.8. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). An attacker must first call the proSol_fileUploadModalProcess handler to poison their own session wi...

CVE-2026-16098

ProSolution WP Client

vulnerable

Aug 18, 2026, 14:08:23
Min -
Max 2.0.11
The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.0.10 via the proSol_handleFileUpload function. This is due to missing validation of the attacker-controlled Content-Disposition header filename, which overrides the allow-listed multipart filename before the file is saved, and a post-save extension check that fails to delete the already-written file. This makes it possible for unauthenticated attackers to upload files that may be exe...

CVE-2026-18807

Elementor Custom Skin

vulnerable

Aug 18, 2026, 14:08:20
Min -
Max 4.3.8
The ECS WordPress plugin before 4.3.8 does not have capability or ownership checks on its dynamic repeater actions, relying only on a nonce available to any user who can open the page builder, allowing users with a contributor-level account or above to read, alter and delete the binding configuration of posts they do not own and to change the ECS WordPress plugin before 4.3.8's site-wide presets.

CVE-2026-14230

Elementor Custom Skin

vulnerable

Aug 18, 2026, 14:08:20
Min -
Max 4.3.8
The ECS WordPress plugin before 4.3.8 does not perform capability or object-ownership checks on its Dynamic Repeater AJAX handlers (gated only by a capability-agnostic nonce that any edit_posts user obtains from the Elementor editor), so a Contributor can write a data-source binding into any post — including admin-authored pages — whose attacker-controlled values are rendered into a widget's repeater output without sanitization, executing JavaScript in the session of any visitor or administrator who views ...

CVE-2026-19613

Elementor Custom Skin

vulnerable

Aug 18, 2026, 14:08:20
Min -
Max 4.3.10
The ECS WordPress plugin before 4.3.10 does not perform ownership or post-status checks when one of its dynamic repeater data sources reads custom field values from a user-supplied post identifier, allowing users with a contributor-level account or above to read custom field values and post metadata from posts they do not own, including private and draft ones.

CVE-2026-14229

Elementor Custom Skin

vulnerable

Aug 18, 2026, 14:08:20
Min -
Max 4.3.8
The ECS WordPress plugin before 4.3.8 does not check the post status or any capability when rendering an Elementor document requested through one of its AJAX actions, allowing unauthenticated users to retrieve the rendered content of unpublished (private, draft, pending) documents by supplying their identifier.

Recent approved applications

Application Date Description Details
Actual on: Aug 18, 2026, 18:08:30

LiteSpeed Cache

Jul 28, 2026, 10:07:24 Caching and optimization plugins sit directly in the path that produces a public page. Their settings can influence stored output, asset delivery, and the content returned to every visitor. LiteSpeed Cache version 7.8.1 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64675, confirming that the plugin was reviewed from a secure code perspective with attention to cache isolation, purge controls, generated assets, optimization requests, and privileged settin...

Smush &#8211; Optimize, Compress and Lazy Load Images

Jul 28, 2026, 10:07:24 Image optimization plugins process files that become part of nearly every public page. Compression, format conversion, lazy loading, and CDN delivery all need careful handling of uploads, metadata, and generated URLs. Smush - Image Optimization, Compression, Lazy Load, WebP & CDN version 4.2.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64676, confirming that the plugin was reviewed from a secure code perspective with attention to image processing inp...

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress

Jul 28, 2026, 10:07:24 Form builders accept untrusted input from public visitors and turn it into stored records, notifications, and administrator workflows. Secure validation, permission checks, and careful output handling are central to every submission path. Ninja Forms - The Contact Form Builder That Grows With You version 3.14.11 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64678, confirming that the plugin was reviewed from a secure code perspective with attention to p...

Premium Addons for Elementor

Jul 28, 2026, 10:07:24 Elementor extension packs add widgets, templates, display rules, and dynamic output to the page builder. Because saved widget settings become public HTML, secure rendering and protected editor actions are essential. Premium Addons for Elementor - Powerful Elementor Templates & Widgets version 4.11.89 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64677, confirming that the plugin was reviewed from a secure code perspective with attention to widget config...

Template Kit &#8211; Import

Jul 28, 2026, 10:07:24 Template import tools bring structured design data and assets into a WordPress installation. Import permissions, file validation, remote resources, and the safety of stored page content all matter before an imported kit reaches the public site. Template Kit - Import version 1.0.16 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64682, confirming that the plugin was reviewed from a secure code perspective with attention to import authorization, package val...

Intuitive Custom Post Order

Jul 28, 2026, 10:07:24 Content ordering plugins turn drag-and-drop administrator actions into persistent changes across posts, pages, taxonomies, and sites. Those updates must be limited to authorized objects and protected from forged requests. Intuitive Custom Post Order version 3.2.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64683, confirming that the plugin was reviewed from a secure code perspective with attention to reorder permissions, request integrity, object iden...

Honeypot for Contact Form 7

Jul 28, 2026, 10:07:24 Contact Form 7 extensions can influence spam checks, stored submissions, redirects, and outbound webhooks. These features cross the boundary between anonymous form input, privileged records, external destinations, and front-end responses. CF7 Apps - Honeypot, Database, Redirection, Webhook, and Addons for Contact Form 7 version 3.6.1 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64684, confirming that the plugin was reviewed from a secure code perspecti...

WooCommerce Legacy REST API

Jul 28, 2026, 10:07:24 Commerce APIs expose structured access to products, orders, customers, and store operations. A compatibility plugin that restores legacy endpoints must enforce authentication and permissions consistently across every request. WooCommerce Legacy REST API version 1.0.5 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64680, confirming that the plugin was reviewed from a secure code perspective with attention to API authentication, request authorization, obje...

Jetpack – WP Security, Backup, Speed, & Growth

Jun 25, 2026, 16:06:39 Security and performance suites operate across many areas of a WordPress installation, including backups, malware scanning, content delivery, statistics, forms, and social publishing. That makes them operationally useful, but also security-sensitive because a broad plugin footprint can affect privileged settings, connected service tokens, public scripts, and administrator workflows. Jetpack - WP Security, Backup, Speed, and Growth version 15.9.1 has successfully completed the CleanTalk Plugin Security Certi...

Admin and Site Enhancements (ASE)

Jun 25, 2026, 16:06:39 Administrative enhancement plugins concentrate many privileged controls in one interface, including editor behavior, media tools, SMTP settings, menu changes, and site management modules. That makes them efficient for administrators, but also security-sensitive because broad settings can affect core WordPress behavior. Admin and Site Enhancements (ASE) version 8.8.5 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64673, confirming that the plugin was revi...