cleantalk

Vulnerabilities and Security Researches

Recent vulnerability researches

CVE/PSC Application Date Affected versions Description
Actual on: Sep 07, 2026, 02:09:58

CVE-2026-85311

MarketKing — Ultimate WooCommerce Multivendor Marketplace Solution

vulnerable

Sep 06, 2026, 19:09:09
Min -
Max 2.1.70
Missing Authorization vulnerability in Kings Plugins MarketKing allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MarketKing: from n/a through 2.1.60.

CVE-2024-11080

Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks

vulnerable

Sep 06, 2026, 18:09:16
Min -
Max 2.3.33
The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Unauthenticated Hook Injection in versions 2.2.32 to 2.3.1 via several functions in the ~/includes/blocks/form-wrap/function.php file. This makes it possible for unauthenticated attackers to execute actions with hooks in WordPress, granted no other security controls are present in the function.

CVE-2026-83625

Contact Form by Supsystic

vulnerable

Sep 06, 2026, 17:09:30
Min -
Max 1.10.3
The Contact Form by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via IP Address Header in all versions up to, and including, 1.10.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. An unauthenticated attacker can first call the 'updateNonce' action — which is accessible without authentication due to its absence fr...

CVE-2026-84045

Taxi Booking Manager for WooCommerce – WordPress plugin | Ecab

vulnerable

Sep 06, 2026, 17:09:16
Min -
Max 2.0.5
The E-cab Taxi Booking Manager for Woocommerce WordPress plugin before 2.0.5 does not validate a client-supplied trip distance and base-price value on the server before pricing a booking, allowing unauthenticated attackers to manipulate the order total down to zero and place real taxi-booking orders at an arbitrary price.

CVE-2026-84043

ePayco plugin for WooCommerce

vulnerable

Sep 06, 2026, 14:09:49
Min -
Max 8.4.7
The ePayco Payment Gateway for WooCommerce WordPress plugin before 8.4.7 does not properly verify the authenticity of payment confirmation requests, allowing unauthenticated attackers to mark orders as paid without a valid gateway signature.

CVE-2026-13447

MStore API

vulnerable

Sep 06, 2026, 13:09:36
Min -
Max 4.21.1
The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and including, 4.20.0 This is due to missing cryptographic signature verification in the FirebasePhoneAuthHelper::verify_id_token() function, which decodes and validates Firebase ID token claims (alg, kid, aud, iss) but never calls openssl_verify() or any equivalent to validate the JWT signature against Google's actual public key certificates. This makes it possible for unauthenticated attackers to ...

CVE-2026-75018

Custom Contact Forms

vulnerable

Sep 06, 2026, 12:09:45
Min -
Max 7.16.1
The Custom Contact Forms plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.16. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to permanently force-delete arbitrary posts of any post type (including pages, administrator-authored posts, and WooCommerce products) and write arbitrary ccf_field_* post meta onto any post reg...

CVE-2026-84066

Directorist – WordPress Business Directory Plugin with Classified Ads Listings

vulnerable

Sep 06, 2026, 12:09:15
Min -
Max 8.9
The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9 does not verify that the requesting user owns the post being modified before writing uploaded file references to its metadata, allowing users with the subscriber role and above to overwrite image metadata on posts belonging to other users.

CVE-2026-84044

Restaurant Menu and Food Ordering

vulnerable

Sep 06, 2026, 11:09:43
Min -
Max 2.4.12
The Restaurant Menu and Food Ordering WordPress plugin before 2.4.12 does not verify that a PayPal payment notification genuinely originates from PayPal, allowing unauthenticated attackers to forge a payment notification and mark their own order as paid and completed without making any payment.

CVE-2026-19887

Welcart e-Commerce

vulnerable

Sep 06, 2026, 11:09:10
Min -
Max 2.12.2
The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.12.1 via deserialization of untrusted input in the Telecom EDY payment callback (usces_action_acting_transaction). Unauthenticated attackers can store arbitrary 'reserve' key/value pairs as order metadata during a public checkout, then invoke the callback with an attacker-chosen 'option' parameter to select and unserialize that metadata without any provider signature, source-address, tra...

Recent approved applications

Application Date Description Details
Actual on: Sep 07, 2026, 02:09:58

Health Check & Troubleshooting

Aug 25, 2026, 23:08:42 Diagnostic plugins inspect server and WordPress configuration, collect debug data, verify files and email delivery, and alter plugin or theme state for a troubleshooting session. Health Check & Troubleshooting version 1.7.1 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64692, confirming that the review focused on privileged diagnostics, session isolation, debug data disclosure, file integrity checks, tool requests, and temporary troubleshooting controls...

Limit Login Attempts

Aug 25, 2026, 23:08:42 Login protection plugins operate directly on authentication requests, retry counters, lockouts, cookies, client addresses, and administrative notifications. Limit Login Attempts version 1.7.2 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64690, confirming that the review focused on retry tracking, IP handling, lockout enforcement, authentication cookie checks, configuration access, and safe logging of failed attempts.

Force Regenerate Thumbnails

Aug 25, 2026, 23:08:42 Thumbnail regeneration tools delete derived image sizes, read original uploads, create replacement files, and execute batch operations across the media library. Force Regenerate Thumbnails version 2.3.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64694, confirming that the review focused on attachment authorization, path confinement, batch requests, file deletion scope, image processing inputs, and progress handling.

Advanced Google reCAPTCHA

Aug 25, 2026, 23:08:42 CAPTCHA integrations sit on public login, registration, password reset, comment, commerce, and community forms where untrusted requests meet account and content workflows. Advanced Google reCAPTCHA version 5.40 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64693, confirming that the review focused on token verification, protected form coverage, settings authorization, remote API handling, bypass resistance, and safe failure behavior.

Complianz – Terms and Conditions

Aug 25, 2026, 23:08:42 Legal document generators collect business and website details, store wizard answers, publish generated pages, and may process consumer withdrawal submissions. Complianz - Terms and Conditions version 1.4.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64691, confirming that the review focused on wizard permissions, stored configuration, document output, withdrawal form requests, email handling, anti-abuse controls, and safe rendering of generated text.

Site Kit by Google – Analytics, Search Console, AdSense, Speed

Aug 25, 2026, 00:08:21 Analytics and advertising integrations connect a WordPress dashboard to external services and expose site performance data to privileged users. Site Kit by Google - Analytics, Search Console, AdSense, Speed version 1.186.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64685, confirming that the review focused on service connections, dashboard data access, REST requests, administrator actions, and safe rendering of remote metrics.

Disable Comments – Remove Comments & Stop Spam [Multi-Site Support]

Aug 25, 2026, 00:08:21 Comment management tools affect public submission paths, administration screens, feeds, APIs, and multisite policy. Disable Comments - Remove Comments & Stop Spam [Multi-Site Support] version 2.8.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64686, confirming that the review focused on settings access, request validation, comment-related endpoints, role-aware controls, and consistent enforcement across supported site contexts.

Admin Menu Editor

Aug 25, 2026, 00:08:21 Dashboard customization tools influence navigation, capability checks, menu visibility, redirects, and access to administrative screens. Admin Menu Editor version 1.15.2 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64688, confirming that the review focused on settings authorization, capability handling, menu configuration integrity, redirect behavior, and safe processing of custom labels, URLs, and icons.

WebP Express

Aug 25, 2026, 00:08:21 Image conversion plugins process uploaded files, write derivatives, update rewrite rules, and may invoke local or remote converters. WebP Express version 0.25.15 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64689, confirming that the review focused on file access, conversion inputs, generated output paths, rewrite behavior, converter configuration, and protection of privileged settings.

Premium Addons for Elementor

Jul 28, 2026, 10:07:24 Elementor extension packs add widgets, templates, display rules, and dynamic output to the page builder. Because saved widget settings become public HTML, secure rendering and protected editor actions are essential. Premium Addons for Elementor - Powerful Elementor Templates & Widgets version 4.11.89 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64677, confirming that the plugin was reviewed from a secure code perspective with attention to widget config...