cleantalk

Vulnerabilities and Security Researches

Recent vulnerability researches

CVE/PSC Application Date Affected versions Description
Actual on: Aug 04, 2026, 22:08:43

CVE-2026-16273

Narrative Publisher

vulnerable

Aug 05, 2026, 02:08:50
Min -
Max 1.0.7
The Narrative Publisher WordPress plugin through 1.0.7 does not restrict write access to a REST-exposed post meta field or escape it when rendering, allowing users with contributor-level access and above to store JavaScript that executes in the browser of any higher-privileged user who views the affected post.

CVE-2026-13340

SVG Support

vulnerable

Aug 05, 2026, 02:08:30
Min -
Max 2.5.17
The SVG Support WordPress plugin before 2.5.17 does not apply its SVG sanitisation to uploaded files using the .svgz extension, even though it registers and serves them as SVG, allowing a user permitted to upload SVGs (such as an Author once granted upload access) to store a script-bearing file that executes in the browser of anyone who later views it, including an administrator.

CVE-2026-15234

Codeless Page Builder

vulnerable

Aug 05, 2026, 01:08:01
Min -
Max 1.1.4
The Codeless Page Builder WordPress plugin through 1.1.4 does not sanitize or validate a shortcode attribute before using it as an HTML tag name when rendering content, allowing users with contributor-level access and above to inject arbitrary HTML and JavaScript that executes in the session of any higher-privileged user (such as an administrator) who views the content.

CVE-2026-13329

Buckaroo Woocommerce Payments Plugin

vulnerable

Aug 05, 2026, 00:08:46
Min -
Max 4.9.0
The Buckaroo Woocommerce Payments Plugin WordPress plugin before 4.9.0 does not perform any capability check or nonce validation on an AJAX action that processes payment capture refunds, allowing any authenticated user, including Subscribers, to trigger refunds against captured orders.

CVE-2026-16297

Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer

vulnerable

Aug 05, 2026, 00:08:27
Min -
Max 2.4.3
The Clearfy Cache WordPress plugin before 2.4.3 does not restrict the classes allowed when unserializing settings-import data, allowing users with administrator access to perform PHP Object Injection attacks, which may lead to remote code execution when a suitable gadget chain is present in the environment.

CVE-2026-28147

Unlimited Elements For Elementor (Free Widgets, Addons, Templates)

vulnerable

Aug 05, 2026, 00:08:23
Min -
Max 2.0.16
Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.15.

CVE-2026-16532

Link Library

vulnerable

Aug 04, 2026, 23:08:15
Min -
Max 7.9.3
The Link Library WordPress plugin before 7.9.3 does not properly sanitise and escape a user-supplied value before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.

CVE-2026-15260

GEO my WordPress

vulnerable

Aug 04, 2026, 22:08:13
Min -
Max 4.5.5.3
The GEO my WP WordPress plugin before 4.5.5.3 does not perform any ownership or capability check on two of its logged-in AJAX actions, allowing users with subscriber-level access or above to modify or permanently delete other users' and posts' geolocation records by supplying arbitrary record IDs.

CVE-2026-14309

Chat On Desk Order Notifications – WooCommerce

vulnerable

Aug 04, 2026, 21:08:13
Min -
Max 1.0.9
The Chat On Desk Order Notifications WordPress plugin before 1.0.9 does not verify that the one-time password has been validated before processing a password-reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, and take over their accounts when SMS one-time-password password reset is enabled.

CVE-2026-16292

Frontend File Manager Plugin

vulnerable

Aug 04, 2026, 14:08:37
Min -
Max 23.6
The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on one of its file-metadata update actions, allowing an attacker to modify the metadata of a logged-in user's uploaded file via a CSRF attack, which can be leveraged to download that file. When guest uploads are enabled, the same action is reachable unauthenticated against any user's file.

Recent approved applications

Application Date Description Details
Actual on: Aug 04, 2026, 22:08:43

LiteSpeed Cache

Jul 28, 2026, 10:07:24 Caching and optimization plugins sit directly in the path that produces a public page. Their settings can influence stored output, asset delivery, and the content returned to every visitor. LiteSpeed Cache version 7.8.1 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64675, confirming that the plugin was reviewed from a secure code perspective with attention to cache isolation, purge controls, generated assets, optimization requests, and privileged settin...

Smush – Optimize, Compress and Lazy Load Images

Jul 28, 2026, 10:07:24 Image optimization plugins process files that become part of nearly every public page. Compression, format conversion, lazy loading, and CDN delivery all need careful handling of uploads, metadata, and generated URLs. Smush - Image Optimization, Compression, Lazy Load, WebP & CDN version 4.2.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64676, confirming that the plugin was reviewed from a secure code perspective with attention to image processing inp...

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress

Jul 28, 2026, 10:07:24 Form builders accept untrusted input from public visitors and turn it into stored records, notifications, and administrator workflows. Secure validation, permission checks, and careful output handling are central to every submission path. Ninja Forms - The Contact Form Builder That Grows With You version 3.14.11 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64678, confirming that the plugin was reviewed from a secure code perspective with attention to p...

Premium Addons for Elementor

Jul 28, 2026, 10:07:24 Elementor extension packs add widgets, templates, display rules, and dynamic output to the page builder. Because saved widget settings become public HTML, secure rendering and protected editor actions are essential. Premium Addons for Elementor - Powerful Elementor Templates & Widgets version 4.11.89 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64677, confirming that the plugin was reviewed from a secure code perspective with attention to widget config...

Translate Multilingual sites – TranslatePress

Jul 28, 2026, 10:07:24 Multilingual plugins store translated text and insert it into front-end output across themes and other plugins. Visual editing, language routing, and automatic translation features require firm access controls and consistent escaping. TranslatePress - Translate Multilingual sites with AI Translation version 3.2.6 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64679, confirming that the plugin was reviewed from a secure code perspective with attention to ...

Template Kit – Import

Jul 28, 2026, 10:07:24 Template import tools bring structured design data and assets into a WordPress installation. Import permissions, file validation, remote resources, and the safety of stored page content all matter before an imported kit reaches the public site. Template Kit - Import version 1.0.16 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64682, confirming that the plugin was reviewed from a secure code perspective with attention to import authorization, package val...

Intuitive Custom Post Order

Jul 28, 2026, 10:07:24 Content ordering plugins turn drag-and-drop administrator actions into persistent changes across posts, pages, taxonomies, and sites. Those updates must be limited to authorized objects and protected from forged requests. Intuitive Custom Post Order version 3.2.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64683, confirming that the plugin was reviewed from a secure code perspective with attention to reorder permissions, request integrity, object iden...

Honeypot for Contact Form 7

Jul 28, 2026, 10:07:24 Contact Form 7 extensions can influence spam checks, stored submissions, redirects, and outbound webhooks. These features cross the boundary between anonymous form input, privileged records, external destinations, and front-end responses. CF7 Apps - Honeypot, Database, Redirection, Webhook, and Addons for Contact Form 7 version 3.6.1 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64684, confirming that the plugin was reviewed from a secure code perspecti...

WooCommerce Legacy REST API

Jul 28, 2026, 10:07:24 Commerce APIs expose structured access to products, orders, customers, and store operations. A compatibility plugin that restores legacy endpoints must enforce authentication and permissions consistently across every request. WooCommerce Legacy REST API version 1.0.5 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64680, confirming that the plugin was reviewed from a secure code perspective with attention to API authentication, request authorization, obje...

Jetpack – WP Security, Backup, Speed, & Growth

Jun 25, 2026, 16:06:39 Security and performance suites operate across many areas of a WordPress installation, including backups, malware scanning, content delivery, statistics, forms, and social publishing. That makes them operationally useful, but also security-sensitive because a broad plugin footprint can affect privileged settings, connected service tokens, public scripts, and administrator workflows. Jetpack - WP Security, Backup, Speed, and Growth version 15.9.1 has successfully completed the CleanTalk Plugin Security Certi...