cleantalk

Vulnerabilities and Security Researches

Recent vulnerability researches

CVE/PSC Application Date Affected versions Description
Actual on: Sep 01, 2026, 02:09:08

CVE-2026-14835

SOGO Add Script to Individual Pages Header Footer

vulnerable

Sep 01, 2026, 06:09:55
Min -
Max 3.9
The SOGO Add Script to Individual Pages Header Footer WordPress plugin through 3.9 does not sanitise or escape the custom header/footer script values saved from its post metabox, and does not restrict them to users with the unfiltered_html capability, allowing users with contributor-level access and above to store JavaScript that executes in the browser of any administrator who reviews the post and of any visitor once the post is published.

CVE-2026-78364

MW WP Form

vulnerable

Sep 01, 2026, 06:09:45
Min -
Max 5.1.6
The MW WP Form WordPress plugin before 5.1.6 does not sanitise and escape some of its form settings before outputting them back in an admin dashboard page, which could allow users with a role as low as Editor to perform Stored Cross-Site Scripting attacks against high privilege users such as admin.

CVE-2026-81765

Tailored Tools

vulnerable

Sep 01, 2026, 06:09:10
Min -
Max 3.0.3
Unauthenticated Cross Site Scripting (XSS) in Tailored Tools <= 3.0.2 versions.

CVE-2026-81346

Frontend Admin by DynamiApps

vulnerable

Sep 01, 2026, 05:09:47
Min -
Max 3.29.11
The Frontend Admin by DynamiApps WordPress plugin before 3.29.11 does not perform a capability check on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to delete arbitrary membership plans.

CVE-2026-16061

Rest Routes – Custom Endpoints for WordPress REST API

vulnerable

Sep 01, 2026, 05:09:40
Min -
Max 5.5.5
The Rest Routes WordPress plugin through 5.5.5 does not sanitize and validate a value taken from the URL of one of its public REST routes before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks.

CVE-2026-81660

WordPress CRM, Email &amp; Marketing Automation for WordPress | Award Winner — Groundhogg

vulnerable

Sep 01, 2026, 03:09:07
Min -
Max 4.5.13
The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin before 4.5.13 does not validate or escape values submitted to some optional web form fields before storing them and outputting them back in an administrative area, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against high privilege users.

CVE-2026-80488

Import CSV or XML Datafeed With Ease

vulnerable

Aug 31, 2026, 17:08:43
Min -
Max 9.0
The WP Ultimate CSV Importer WordPress plugin before 9.0 does not properly sanitise and escape imported field values before using them in a SQL statement, which could allow high privilege users such as admin to perform SQL injection attacks.

CVE-2026-76546

User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor

vulnerable

Aug 31, 2026, 16:08:10
Min -
Max 4.0.1
The User Profile Builder WordPress plugin before 4.0.1 does not escape the output of one of its optional shortcodes, allowing users with a role as low as contributor to perform Stored Cross-Site Scripting attacks against any user viewing the affected content, including administrators. The shortcode is not enabled by default.

CVE-2026-76547

User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor

vulnerable

Aug 31, 2026, 16:08:10
Min -
Max 4.0.1
The User Profile Builder WordPress plugin before 4.0.1 does not validate the type of data being deserialized when importing a configuration file, allowing high privilege users such as administrators to conduct PHP Object Injection. The affected feature is a free add-on which is disabled by default, and no POP chain is present in the User Profile Builder WordPress plugin before 4.0.1 itself, so further impact requires a suitable gadget from another installed User Profile Builder WordPress plugin before 4....

CVE-2026-76548

User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor

vulnerable

Aug 31, 2026, 16:08:10
Min -
Max 4.0.1
The User Profile Builder WordPress plugin before 4.0.1 does not properly restrict its front-end file upload feature, granting unauthenticated visitors capabilities reserved to privileged roles. This allows them to list the site's media library and to modify unpublished posts, pages and media items belonging to other users.

Recent approved applications

Application Date Description Details
Actual on: Sep 01, 2026, 02:09:08

Health Check & Troubleshooting

Aug 25, 2026, 23:08:42 Diagnostic plugins inspect server and WordPress configuration, collect debug data, verify files and email delivery, and alter plugin or theme state for a troubleshooting session. Health Check & Troubleshooting version 1.7.1 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64692, confirming that the review focused on privileged diagnostics, session isolation, debug data disclosure, file integrity checks, tool requests, and temporary troubleshooting controls...

Limit Login Attempts

Aug 25, 2026, 23:08:42 Login protection plugins operate directly on authentication requests, retry counters, lockouts, cookies, client addresses, and administrative notifications. Limit Login Attempts version 1.7.2 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64690, confirming that the review focused on retry tracking, IP handling, lockout enforcement, authentication cookie checks, configuration access, and safe logging of failed attempts.

Force Regenerate Thumbnails

Aug 25, 2026, 23:08:42 Thumbnail regeneration tools delete derived image sizes, read original uploads, create replacement files, and execute batch operations across the media library. Force Regenerate Thumbnails version 2.3.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64694, confirming that the review focused on attachment authorization, path confinement, batch requests, file deletion scope, image processing inputs, and progress handling.

Advanced Google reCAPTCHA

Aug 25, 2026, 23:08:42 CAPTCHA integrations sit on public login, registration, password reset, comment, commerce, and community forms where untrusted requests meet account and content workflows. Advanced Google reCAPTCHA version 5.40 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64693, confirming that the review focused on token verification, protected form coverage, settings authorization, remote API handling, bypass resistance, and safe failure behavior.

Complianz &#8211; Terms and Conditions

Aug 25, 2026, 23:08:42 Legal document generators collect business and website details, store wizard answers, publish generated pages, and may process consumer withdrawal submissions. Complianz - Terms and Conditions version 1.4.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64691, confirming that the review focused on wizard permissions, stored configuration, document output, withdrawal form requests, email handling, anti-abuse controls, and safe rendering of generated text.

Site Kit by Google &#8211; Analytics, Search Console, AdSense, Speed

Aug 25, 2026, 00:08:21 Analytics and advertising integrations connect a WordPress dashboard to external services and expose site performance data to privileged users. Site Kit by Google - Analytics, Search Console, AdSense, Speed version 1.186.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64685, confirming that the review focused on service connections, dashboard data access, REST requests, administrator actions, and safe rendering of remote metrics.

Disable Comments &#8211; Remove Comments &amp; Stop Spam [Multi-Site Support]

Aug 25, 2026, 00:08:21 Comment management tools affect public submission paths, administration screens, feeds, APIs, and multisite policy. Disable Comments - Remove Comments & Stop Spam [Multi-Site Support] version 2.8.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64686, confirming that the review focused on settings access, request validation, comment-related endpoints, role-aware controls, and consistent enforcement across supported site contexts.

Admin Menu Editor

Aug 25, 2026, 00:08:21 Dashboard customization tools influence navigation, capability checks, menu visibility, redirects, and access to administrative screens. Admin Menu Editor version 1.15.2 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64688, confirming that the review focused on settings authorization, capability handling, menu configuration integrity, redirect behavior, and safe processing of custom labels, URLs, and icons.

WebP Express

Aug 25, 2026, 00:08:21 Image conversion plugins process uploaded files, write derivatives, update rewrite rules, and may invoke local or remote converters. WebP Express version 0.25.15 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64689, confirming that the review focused on file access, conversion inputs, generated output paths, rewrite behavior, converter configuration, and protection of privileged settings.

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress

Jul 28, 2026, 10:07:24 Form builders accept untrusted input from public visitors and turn it into stored records, notifications, and administrator workflows. Secure validation, permission checks, and careful output handling are central to every submission path. Ninja Forms - The Contact Form Builder That Grows With You version 3.14.11 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64678, confirming that the plugin was reviewed from a secure code perspective with attention to p...