cleantalk

Vulnerabilities and Security Researches

Recent vulnerability researches

CVE/PSC Application Date Affected versions Description
Actual on: Aug 29, 2026, 00:08:52

CVE-2026-76053

Translate Multilingual sites – TranslatePress

vulnerable

Aug 29, 2026, 05:08:49
Min -
Max 3.3.4
The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Noise-Key Injection into HTML Parser in all versions up to, and including, 3.3.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation is possible because WordPress's comment KSES allowlist ...

CVE-2026-78257

Rental and Booking Manager for Bike, Car, Dress, Resort with WooCommerce Integration – WpRently | WordPress plugin

vulnerable

Aug 29, 2026, 05:08:38
Min -
Max 2.7.6
Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions.

CVE-2026-3129

LiteSpeed Cache

vulnerable

Aug 29, 2026, 05:08:05
Min -
Max 7.8
The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted `<img>` tag attributes in all versions up to, and including, 7.7. This is due to a flawed regular expression that is used to strip `width` and `height` attributes from images when the "Lazy Load Images" and "Add Missing Sizes" features are enabled. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that execute whenever a user accesse...

CVE-2026-18978

LiteSpeed Cache

vulnerable

Aug 29, 2026, 05:08:05
Min -
Max 7.9
The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 7.8.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. A comment payload crafted exclusively from decimal numeric character references (e.g. &#34;, &#60;, &#62;) placed inside an allowed element such as...

CVE-2026-81271

GeoDirectory &#8211; WordPress Business Directory Plugin, or Classified Directory

vulnerable

Aug 29, 2026, 05:08:01
Min -
Max 2.8.177
Unauthenticated Cross Site Request Forgery (CSRF) in GeoDirectory <= 2.8.176 versions.

CVE-2026-81276

Contact Form builder with drag &amp; drop for WordPress &#8211; Kali Forms

vulnerable

Aug 29, 2026, 04:08:25
Min -
Max 2.4.24
Unauthenticated Broken Access Control in Kali Forms <= 2.4.23 versions.

CVE-2026-13415

CMP &#8211; Coming Soon &amp; Maintenance Plugin by NiteoThemes

vulnerable

Aug 29, 2026, 03:08:41
Min -
Max 4.1.18
The CMP WordPress plugin before 4.1.18 does not enforce an option-name allow-list when importing settings via one of its AJAX actions, allowing users with the Editor role (when the administrator has granted the Editor role access to the CMP WordPress plugin before 4.1.18's admin-bar controls) to update arbitrary WordPress options, including options that lead to privilege escalation to Administrator.

CVE-2026-13416

CMP &#8211; Coming Soon &amp; Maintenance Plugin by NiteoThemes

vulnerable

Aug 29, 2026, 03:08:41
Min -
Max 4.1.18
The CMP WordPress plugin before 4.1.18 does not sanitise and escape a settings value before outputting it on the coming-soon page, allowing users with the Editor role (when the administrator has granted the Editor role access to the CMP WordPress plugin before 4.1.18's admin-bar controls) to inject arbitrary web scripts that execute when a visitor views the page.

CVE-2026-13414

CMP &#8211; Coming Soon &amp; Maintenance Plugin by NiteoThemes

vulnerable

Aug 29, 2026, 03:08:41
Min -
Max 4.1.18
The CMP WordPress plugin before 4.1.18 does not perform authorization checks on one of its AJAX actions and relies on a nonce that is skipped for certain (and exposed to anonymous visitors on others), allowing unauthenticated attackers to disable the site's maintenance/coming-soon mode under a non-default countdown configuration.

CVE-2026-18324

Forminator &#8211; Contact Form, Payment Form &amp; Custom Form Builder

vulnerable

Aug 29, 2026, 03:08:36
Min -
Max 1.57.0.2
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Rich-Text Textarea Field in all versions up to, and including, 1.57.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires that the targeted Textarea field has the Rich-Text editor opt...

Recent approved applications

Application Date Description Details
Actual on: Aug 29, 2026, 00:08:52

Health Check & Troubleshooting

Aug 25, 2026, 23:08:42 Diagnostic plugins inspect server and WordPress configuration, collect debug data, verify files and email delivery, and alter plugin or theme state for a troubleshooting session. Health Check & Troubleshooting version 1.7.1 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64692, confirming that the review focused on privileged diagnostics, session isolation, debug data disclosure, file integrity checks, tool requests, and temporary troubleshooting controls...

Limit Login Attempts

Aug 25, 2026, 23:08:42 Login protection plugins operate directly on authentication requests, retry counters, lockouts, cookies, client addresses, and administrative notifications. Limit Login Attempts version 1.7.2 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64690, confirming that the review focused on retry tracking, IP handling, lockout enforcement, authentication cookie checks, configuration access, and safe logging of failed attempts.

Force Regenerate Thumbnails

Aug 25, 2026, 23:08:42 Thumbnail regeneration tools delete derived image sizes, read original uploads, create replacement files, and execute batch operations across the media library. Force Regenerate Thumbnails version 2.3.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64694, confirming that the review focused on attachment authorization, path confinement, batch requests, file deletion scope, image processing inputs, and progress handling.

Advanced Google reCAPTCHA

Aug 25, 2026, 23:08:42 CAPTCHA integrations sit on public login, registration, password reset, comment, commerce, and community forms where untrusted requests meet account and content workflows. Advanced Google reCAPTCHA version 5.40 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64693, confirming that the review focused on token verification, protected form coverage, settings authorization, remote API handling, bypass resistance, and safe failure behavior.

Complianz &#8211; Terms and Conditions

Aug 25, 2026, 23:08:42 Legal document generators collect business and website details, store wizard answers, publish generated pages, and may process consumer withdrawal submissions. Complianz - Terms and Conditions version 1.4.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64691, confirming that the review focused on wizard permissions, stored configuration, document output, withdrawal form requests, email handling, anti-abuse controls, and safe rendering of generated text.

Site Kit by Google &#8211; Analytics, Search Console, AdSense, Speed

Aug 25, 2026, 00:08:21 Analytics and advertising integrations connect a WordPress dashboard to external services and expose site performance data to privileged users. Site Kit by Google - Analytics, Search Console, AdSense, Speed version 1.186.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64685, confirming that the review focused on service connections, dashboard data access, REST requests, administrator actions, and safe rendering of remote metrics.

Disable Comments &#8211; Remove Comments &amp; Stop Spam [Multi-Site Support]

Aug 25, 2026, 00:08:21 Comment management tools affect public submission paths, administration screens, feeds, APIs, and multisite policy. Disable Comments - Remove Comments & Stop Spam [Multi-Site Support] version 2.8.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64686, confirming that the review focused on settings access, request validation, comment-related endpoints, role-aware controls, and consistent enforcement across supported site contexts.

Admin Menu Editor

Aug 25, 2026, 00:08:21 Dashboard customization tools influence navigation, capability checks, menu visibility, redirects, and access to administrative screens. Admin Menu Editor version 1.15.2 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64688, confirming that the review focused on settings authorization, capability handling, menu configuration integrity, redirect behavior, and safe processing of custom labels, URLs, and icons.

WebP Express

Aug 25, 2026, 00:08:21 Image conversion plugins process uploaded files, write derivatives, update rewrite rules, and may invoke local or remote converters. WebP Express version 0.25.15 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64689, confirming that the review focused on file access, conversion inputs, generated output paths, rewrite behavior, converter configuration, and protection of privileged settings.

Breeze &#8211; WordPress Cache Plugin

Aug 25, 2026, 00:08:21 Caching and optimization plugins rewrite responses, manage cache files, and interact with CDNs and remote asset sources. Breeze Cache version 2.5.13 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64687, confirming that the review focused on cache storage, purge operations, optimization settings, remote downloads, administrator controls, and safe handling of generated assets.