cleantalk

Vulnerabilities and Security Researches

Recent vulnerability researches

CVE/PSC Application Date Affected versions Description
Actual on: Sep 19, 2026, 09:09:16

CVE-2026-90887

WP Inventory Manager

vulnerable

Sep 19, 2026, 14:09:09
Min -
Max 2.5.4
Unauthenticated Cross Site Scripting (XSS) in WP Inventory Manager <= 2.5.4 versions.

CVE-2026-17607

WP Inventory Manager

vulnerable

Sep 19, 2026, 14:09:09
Min -
Max 2.5.2
The WP Inventory Manager plugin for WordPress is vulnerable to SQL Injection via the 'where' shortcode attribute of the [wpinventory] shortcode in versions up to, and including, 2.5.1. This is due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query in the WPIMItem::get_all() function — parse_custom_where() only performs html_entity_decode(), strips semicolons, and does field-label name replacements, without using $wpdb->prepare() or a whitelis...

CVE-2026-14323

Printcart Web to Print Product Designer for WooCommerce

vulnerable

Sep 19, 2026, 14:09:06
Min -
Max 2.8.6
The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.8.5 via the 'mockups' parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. A valid nonce is obtainable by unauthenticated users via the companion nbd_check_use_logged_in nopriv AJAX endpoint, which freely mints and returns a nbdesigner-get-data no...

CVE-2026-12954

Mapster WP Maps

vulnerable

Sep 19, 2026, 13:09:59
Min -
Max 1.24.0
The Mapster WP Maps plugin for WordPress is vulnerable to Arbitrary User Meta Write in all versions up to, and including, 1.23.0 via the `my_profile_update()` function. This is due to the function performing no nonce verification, no capability check, and no allowlist validation on the meta key supplied via the `acf-photo-gallery-groups` POST parameter before passing both the meta key and its corresponding value directly to `update_user_meta()`. This makes it possible for authenticated attackers, with Subsc...

CVE-2026-18346

TikTok

vulnerable

Sep 19, 2026, 13:09:43
Min -
Max 1.4.2
TikTok [tiktok-for-business] < 1.4.2 CVE-2026-18346

CVE-2026-89330

EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps &amp; Embed Any Documents in Gutenberg

vulnerable

Sep 19, 2026, 13:09:42
Min -
Max 4.6.6
The EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'unique' parameter in all versions up to, and including, 4.6.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. This...

CVE-2026-91017

Robokassa payment gateway for Woocommerce

vulnerable

Sep 19, 2026, 13:09:30
Min -
Max 1.8.9
The Robokassa payment gateway for Woocommerce WordPress plugin before 1.8.9 does not verify the authenticity of incoming payment notifications when its non-default deferred-payment feature is enabled, allowing unauthenticated attackers to forge a notification and mark arbitrary WooCommerce orders as paid or on-hold without payment or a valid signature.

CVE-2026-89413

WordPress Filter Gallery Plugin

vulnerable

Sep 19, 2026, 12:09:56
Min -
Max 1.1.5
The Filter Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete any arbitrary Filter Gallery records — including all associated filters, image mappings, settings, and details options — by supplying attacker-controlled gallery IDs. The nonce bypass requir...

CVE-2026-89138

WordPress Filter Gallery Plugin

vulnerable

Sep 19, 2026, 12:09:56
Min -
Max 1.1.5
The Filter Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the title and content of arbitrary WordPress posts, write the _wp_attachment_image_alt meta key on arbitrary posts, and create or overwrite arbitrary ufg_gallery_* options.

CVE-2026-88795

wpShopGermany IT-RECHT KANZLEI

vulnerable

Sep 19, 2026, 11:09:40
Min -
Max 2.4
The wpShopGermany IT-RECHT KANZLEI WordPress plugin before 2.4 does not generate its API authentication token securely, deriving it from data the requester controls and creating it as a side effect of the check that is supposed to validate it, allowing unauthenticated attackers to predict the token and use the access it grants to write arbitrary files, leading to remote code execution.

Recent approved applications

Application Date Description Details
Actual on: Sep 19, 2026, 09:09:16

Child Theme Configurator

Sep 18, 2026, 11:09:14 Child theme utilities inspect installed themes and can create or modify PHP, CSS, and configuration files inside the WordPress themes directory. Child Theme Configurator version 2.6.7 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65697. The review focused on administrative authorization, filesystem boundaries, theme and file selection, stylesheet parsing, template copying, and safe handling of configuration input.

WP Mail Logging

Sep 18, 2026, 11:09:14 Email logging plugins retain message bodies, recipient details, headers, attachments, and delivery errors that may contain sensitive operational data. WP Mail Logging version 1.16.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65696. The review focused on log access, stored message rendering, attachment references, search and bulk actions, resend requests, and protection of plugin settings.

Health Check & Troubleshooting

Aug 25, 2026, 23:08:42 Diagnostic plugins inspect server and WordPress configuration, collect debug data, verify files and email delivery, and alter plugin or theme state for a troubleshooting session. Health Check & Troubleshooting version 1.7.1 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64692, confirming that the review focused on privileged diagnostics, session isolation, debug data disclosure, file integrity checks, tool requests, and temporary troubleshooting controls...

Limit Login Attempts

Aug 25, 2026, 23:08:42 Login protection plugins operate directly on authentication requests, retry counters, lockouts, cookies, client addresses, and administrative notifications. Limit Login Attempts version 1.7.2 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64690, confirming that the review focused on retry tracking, IP handling, lockout enforcement, authentication cookie checks, configuration access, and safe logging of failed attempts.

Force Regenerate Thumbnails

Aug 25, 2026, 23:08:42 Thumbnail regeneration tools delete derived image sizes, read original uploads, create replacement files, and execute batch operations across the media library. Force Regenerate Thumbnails version 2.3.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64694, confirming that the review focused on attachment authorization, path confinement, batch requests, file deletion scope, image processing inputs, and progress handling.

Advanced Google reCAPTCHA

Aug 25, 2026, 23:08:42 CAPTCHA integrations sit on public login, registration, password reset, comment, commerce, and community forms where untrusted requests meet account and content workflows. Advanced Google reCAPTCHA version 5.40 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64693, confirming that the review focused on token verification, protected form coverage, settings authorization, remote API handling, bypass resistance, and safe failure behavior.

Complianz &#8211; Terms and Conditions

Aug 25, 2026, 23:08:42 Legal document generators collect business and website details, store wizard answers, publish generated pages, and may process consumer withdrawal submissions. Complianz - Terms and Conditions version 1.4.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64691, confirming that the review focused on wizard permissions, stored configuration, document output, withdrawal form requests, email handling, anti-abuse controls, and safe rendering of generated text.

Disable Comments &#8211; Remove Comments &amp; Stop Spam [Multi-Site Support]

Aug 25, 2026, 00:08:21 Comment management tools affect public submission paths, administration screens, feeds, APIs, and multisite policy. Disable Comments - Remove Comments & Stop Spam [Multi-Site Support] version 2.8.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64686, confirming that the review focused on settings access, request validation, comment-related endpoints, role-aware controls, and consistent enforcement across supported site contexts.

Admin Menu Editor

Aug 25, 2026, 00:08:21 Dashboard customization tools influence navigation, capability checks, menu visibility, redirects, and access to administrative screens. Admin Menu Editor version 1.15.2 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64688, confirming that the review focused on settings authorization, capability handling, menu configuration integrity, redirect behavior, and safe processing of custom labels, URLs, and icons.

WebP Express

Aug 25, 2026, 00:08:21 Image conversion plugins process uploaded files, write derivatives, update rewrite rules, and may invoke local or remote converters. WebP Express version 0.25.15 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64689, confirming that the review focused on file access, conversion inputs, generated output paths, rewrite behavior, converter configuration, and protection of privileged settings.