cleantalk

Vulnerabilities and Security Researches

Recent vulnerability researches

CVE/PSC Application Date Affected versions Description
Actual on: Oct 05, 2026, 04:10:37

CVE-2026-91022

Motors – Car Dealer, Classifieds & Listing

vulnerable

Oct 04, 2026, 23:10:48
Min -
Max 1.4.124
The Motors WordPress plugin before 1.4.124 does not sanitise and escape a listing badge setting before outputting it inside an HTML attribute, allowing users with a custom, administrator-assigned listing-management role to inject arbitrary web scripts that execute when a listing is viewed by any visitor, including an administrator.

CVE-2026-79618

WP User Frontend – Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submiss

vulnerable

Oct 04, 2026, 14:10:01
Min -
Max 4.3.12
The WP User Frontend WordPress plugin before 4.3.12 does not enforce its subscription-purchase requirement in one of its post-creation handlers, allowing authenticated users with subscriber-level access and above to create and, depending on the form's configuration, immediately publish posts through forms restricted to paying subscribers.

CVE-2026-90952

Wp Edit Password Protected – Create Member/User Only Page & Design Password Protected Form

vulnerable

Oct 04, 2026, 10:10:22
Min 2.0.0
Max 2.0.7
The WP Edit Password Protected WordPress plugin before 2.0.7 does not enforce its site-wide access restriction on the WordPress REST API, allowing unauthenticated users to read the content of published posts and pages that the site's access mode was configured to hide.

CVE-2026-90988

Request a Quote

vulnerable

Oct 04, 2026, 10:10:04
Min -
Max 2.5.6
The Request a Quote WordPress plugin through 2.5.6 does not perform an authorization check on one of its unauthenticated AJAX handlers, allowing unauthenticated users to read the contact records of quote-request submissions, including records the site has not published.

CVE-2026-85005

Popup Maker – Responsive popup, Exit Intent Pop up, Email Optins, Autoresponder & More

vulnerable

Oct 04, 2026, 09:10:50
Min -
Max 1.4.5
The Popup Maker WP WordPress plugin through 1.4.5 does not perform authorization checks on several of its actions and exposes its management page to any logged-in user, allowing users with a low-privileged role such as Subscriber to store display-targeting values that are later invoked as zero-argument PHP callables on public page loads, leading to sensitive information disclosure and denial of service.

CVE-2026-85004

Popup Maker – Responsive popup, Exit Intent Pop up, Email Optins, Autoresponder & More

vulnerable

Oct 04, 2026, 09:10:50
Min -
Max 1.4.5
The Popup Maker WordPress plugin through 1.4.5 does not perform a capability check on one of its account-connection actions, only verifying a nonce, allowing authenticated users with minimal privileges such as Subscribers to overwrite a site-wide Popup Maker WordPress plugin through 1.4.5 option (the linked service account and API configuration) that should only be modifiable by administrators.

CVE-2026-13718

Tabs Responsive – With WooCommerce Product Tabs Extension

vulnerable

Oct 04, 2026, 08:10:38
Min -
Max 2.5
The Tabs Responsive WordPress plugin through 2.5 does not sanitize the content of WooCommerce product tabs before storing and rendering it, allowing a shop manager to store JavaScript that executes when any user, including an administrator, views the product page.

CVE-2026-39601

WP Booking Calendar

vulnerable

Oct 04, 2026, 08:10:05
Min -
Max 11.8.4
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in WPdevelop Booking Calendar booking allows Leveraging Race Conditions.This issue affects Booking Calendar: from n/a through 11.8.4.

CVE-2026-84740

The Events Calendar

vulnerable

Oct 04, 2026, 07:10:28
Min 6.12.0
Max 6.17.5.1
The Events Calendar WordPress plugin before 6.17.5.1 does not validate or sanitise data submitted to an unauthenticated AJAX action before merging it into its rendering context, allowing unauthenticated users to execute arbitrary shortcodes registered on the site.

CVE-2026-87920

W3 Total Cache

vulnerable

Oct 04, 2026, 07:10:00
Min -
Max 2.10.7
The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via Output-Buffer Regex Rewrite in all versions up to, and including, 2.10.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability is only exploitable when the 'Remove query strings from static resources' option is enabled in W...