cleantalk

Vulnerabilities and Security Researches

Recent vulnerability researches

CVE/PSC Application Date Affected versions Description
Actual on: Oct 08, 2026, 00:10:13

CVE-2026-89417

OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy.

vulnerable

Oct 08, 2026, 04:10:55
Min -
Max 6.3.11
The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 's' Search Parameter via comments-atom Feed in all versions up to, and including, 6.3.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires that the front-end server serves the retained...

CVE-2026-39790

VikRentCar Car Rental Management System

vulnerable

Oct 08, 2026, 04:10:47
Min -
Max 1.4.6
Unauthenticated Cross Site Scripting (XSS) in VikRentCar <= 1.4.6 versions.

CVE-2026-103346

Payflex Payment Gateway

vulnerable

Oct 08, 2026, 04:10:18
Min -
Max 2.7.1
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tomlister Payflex Payment Gateway payflex-payment-gateway allows Reflected XSS.This issue affects Payflex Payment Gateway: from n/a through 2.7.1.

CVE-2026-39791

Mailjet Email Marketing

vulnerable

Oct 08, 2026, 03:10:15
Min -
Max 6.2.3
Unauthenticated Sensitive Data Exposure in Mailjet Email Marketing <= 6.2.3 versions.

CVE-2026-94299

elegro Crypto Payment

vulnerable

Oct 08, 2026, 02:10:52
Min -
Max 1.0.1
The elegro Crypto Payment WordPress plugin through 1.0.1 does not require a shared secret to be configured before trusting incoming payment notification requests, allowing unauthenticated attackers to forge payment confirmations and change the status of arbitrary orders on any installation where that secret has been left at its default empty value.

CVE-2026-102915

WordPress + Microsoft Office 365 / Azure AD | LOGIN

vulnerable

Oct 07, 2026, 22:10:15
Min -
Max 44.1
Subscriber Broken Access Control in WPO365 <= 44.1 versions.

CVE-2026-103337

WC Nova Poshta Shipping &#8211; Integration of Nova Poshta delivery service for WooCommerce

vulnerable

Oct 07, 2026, 21:10:51
Min -
Max 1.23.3
Missing Authorization vulnerability in Kirillbdev WC Ukraine Shipping wc-ukr-shipping allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WC Ukraine Shipping: from n/a through 1.23.2.

CVE-2026-103085

WP User Manager &#8211; User Profile Builder &amp; Membership

vulnerable

Oct 07, 2026, 21:10:46
Min -
Max 2.9.21
Improper Access Control vulnerability in WP User Manager WP User Manager wp-user-manager allows Privilege Abuse.This issue affects WP User Manager: from n/a through 2.9.20.

CVE-2026-102386

WP Photo Album Plus

vulnerable

Oct 07, 2026, 21:10:33
Min -
Max 9.3.03.002
Subscriber Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.3.02.003 versions.

CVE-2026-104400

B Blocks &#8211; The ultimate block collection

vulnerable

Oct 07, 2026, 20:10:52
Min -
Max 2.1.9
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins B Blocks b-blocks allows Stored XSS.This issue affects B Blocks: from n/a through 2.1.8.

Recent approved applications

Application Date Description Details
Actual on: Oct 08, 2026, 00:10:13

Disable XML-RPC

Sep 25, 2026, 12:09:44 XML-RPC controls affect remote publishing clients and other integrations that communicate with WordPress through the XML-RPC endpoint. Disable XML-RPC version 1.0.1 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65709. The review focused on plugin bootstrap behavior, filter registration, XML-RPC availability, activation state, compatibility with the WordPress request path, and the absence of unnecessary user input surfaces.

Widget Importer &amp; Exporter

Sep 25, 2026, 12:09:44 Widget migration tools process configuration data that can create or update active and inactive widget instances across a WordPress site. Widget Importer & Exporter version 1.6.1 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65707. The review focused on upload handling, JSON data validation, administrator permissions, widget instance import, export output, duplicate detection, unsupported widgets, and developer hooks.

Instant Indexing for Google

Sep 25, 2026, 12:09:44 Search submission plugins handle site URLs and service credentials while sending manual or automatic requests to external indexing endpoints. Instant Indexing for Google version 1.1.22 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65710. The review focused on settings permissions, credential handling, URL validation, manual and bulk submissions, automatic post events, remote API requests, response output, post type exclusions, and IndexNow controls.

Simple Cloudflare Turnstile &#8211; CAPTCHA Alternative

Sep 25, 2026, 12:09:44 Anti-spam integrations accept challenge tokens on public forms and exchange them with an external verification service before a submission is allowed. Simple CAPTCHA with Cloudflare Turnstile version 1.43.2 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65708. The review focused on settings permissions, key handling, challenge token validation, server side verification, form integration, whitelisting, failsafe behavior, and diagnostic logging.

AMP

Sep 22, 2026, 11:09:27 AMP integrations transform WordPress output, validate generated markup, and may direct visitors between standard and optimized page variants. AMP version 2.5.5 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65701. The review focused on administrative settings, markup sanitization, validation data, template processing, component handling, and safe page delivery.

Converter for Media &#8211; Optimize images | Convert WebP &amp; AVIF

Sep 22, 2026, 11:09:27 Image optimization plugins read files from the uploads directory, create alternative formats, and route visitor requests to generated assets. Converter for Media - Optimize images | Convert WebP & AVIF version 6.6.5 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65700. The review focused on source file validation, path confinement, conversion jobs, generated output, delivery rules, and permission checks around administrative actions.

WP Crontrol

Sep 22, 2026, 11:09:27 Cron management plugins can inspect, create, pause, delete, and immediately execute scheduled tasks that affect many parts of a WordPress site. WP Crontrol version 1.21.2 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65702. The review focused on authorization for event management, request integrity, callback and argument display, custom schedules, URL validation, bulk actions, and exported event data.

Child Theme Configurator

Sep 18, 2026, 11:09:14 Child theme utilities inspect installed themes and can create or modify PHP, CSS, and configuration files inside the WordPress themes directory. Child Theme Configurator version 2.6.7 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65697. The review focused on administrative authorization, filesystem boundaries, theme and file selection, stylesheet parsing, template copying, and safe handling of configuration input.

Health Check & Troubleshooting

Aug 25, 2026, 23:08:42 Diagnostic plugins inspect server and WordPress configuration, collect debug data, verify files and email delivery, and alter plugin or theme state for a troubleshooting session. Health Check & Troubleshooting version 1.7.1 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64692, confirming that the review focused on privileged diagnostics, session isolation, debug data disclosure, file integrity checks, tool requests, and temporary troubleshooting controls...

Limit Login Attempts

Aug 25, 2026, 23:08:42 Login protection plugins operate directly on authentication requests, retry counters, lockouts, cookies, client addresses, and administrative notifications. Limit Login Attempts version 1.7.2 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64690, confirming that the review focused on retry tracking, IP handling, lockout enforcement, authentication cookie checks, configuration access, and safe logging of failed attempts.