cleantalk

Vulnerabilities and Security Researches

Recent vulnerability researches

CVE/PSC Application Date Affected versions Description
Actual on: Sep 10, 2026, 04:09:09

CVE-2026-18021

Beaver Builder – WordPress Page Builder

vulnerable

Sep 09, 2026, 12:09:42
Min -
Max 2.10.3.2
The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.10.3.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

CVE-2026-16502

Page Builder: Live Composer

vulnerable

Sep 09, 2026, 11:09:53
Min -
Max 2.1.19
The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.1.18 via deserialization of untrusted input . This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain i...

CVE-2026-12757

Icegram Express – Email Marketing, Newsletters and Automation for WordPress & WooCommerce

vulnerable

Sep 09, 2026, 10:09:03
Min -
Max 5.9.28
The The Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.9.27. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

CVE-2026-76931

Zephyr Project Manager

vulnerable

Sep 09, 2026, 06:09:59
Min -
Max 3.3.206
The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘message’ parameter in all versions up to, and including, 3.3.205 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Custom-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability can only be exploited when the 'Directly link to project' plugin setting is d...

CVE-2026-12230

LearnPress – WordPress LMS Plugin

vulnerable

Sep 09, 2026, 05:09:47
Min -
Max 4.4.0
The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'layout_custom_css' parameter in all versions up to, and including, 4.3.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2026-2520

WordPress Online Booking and Scheduling Plugin – Bookly

vulnerable

Sep 09, 2026, 05:09:04
Min -
Max 27.3
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'updateAddon' function in all versions up to, and including, 27.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update any plugin with a main file of 'main.php' to its latest version.

CVE-2026-81404

IPGP Visitors Origin

vulnerable

Sep 08, 2026, 22:09:02
Min -
Max 1.6
The IPGP Visitors Origin WordPress plugin before 1.6 does not sanitise or escape user input before reflecting it back in the HTTP response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against users who are tricked into submitting a crafted request.

CVE-2026-84899

VikWidgetsLoader – Collection of Widgets

vulnerable

Sep 08, 2026, 21:09:03
Min -
Max 1.12.0
The VikWidgetsLoader WordPress plugin before 1.12.0 does not sanitise or escape a block attribute before outputting it inside an inline script, allowing users with the Contributor role to store arbitrary JavaScript that executes in the browser of any user viewing the affected post, including the administrator who reviews the pending submission.

CVE-2026-2390

Powerkit – Supercharge your WordPress Site

vulnerable

Sep 08, 2026, 19:09:32
Min -
Max 3.0.5
The Powerkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Lazy Load module's image processing in all versions up to, and including, 3.0.4. This is due to the 'content_process_images' function using a flawed regex-based HTML attribute parser. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2026-84935

HT Menu – WordPress Mega Menu Builder for Elementor

vulnerable

Sep 08, 2026, 17:09:56
Min -
Max 1.2.7
The HT Menu WordPress plugin before 1.2.7 does not perform any capability or object-ownership check when saving navigation menu-item settings, and does not escape those stored settings when the menu is rendered, allowing users with minimal permissions such as Subscribers to store JavaScript that executes in the browser of any visitor, administrators included, who views the affected menu.