cleantalk

Vulnerabilities and Security Researches

Recent vulnerability researches

CVE/PSC Application Date Affected versions Description
Actual on: Sep 16, 2026, 05:09:36

CVE-2026-74933

GenieWords

vulnerable

Sep 16, 2026, 02:09:21
Min -
Max 1.5.27
The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have authorisation checks on some of its REST API and AJAX actions, and decodes stored values before printing them, allowing unauthenticated users to overwrite its configuration and inject arbitrary web scripts that execute on every front-end page.

CVE-2026-85129

Hoo Companion

vulnerable

Sep 16, 2026, 02:09:10
Min -
Max 1.0.2
The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or validation checks in one of its import features, and does not sanitise the data submitted to it before storing it as the active theme's settings, allowing unauthenticated attackers to inject arbitrary web scripts which will execute for anyone viewing the site, including administrators. The same request destroys the site's existing theme settings.

CVE-2026-15758

3D FlipBook – PDF Flipbook WordPress

vulnerable

Sep 16, 2026, 00:09:11
Min -
Max 1.16.21
The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.16.20 via the 'id' parameter. This makes it possible for unauthenticated attackers to extract sensitive data including the full metadata payload of password-protected flipbooks — including title, outline, props, and the serialized data blob containing the underlying PDF file's direct URL — bypassing WordPress post-password co...

CVE-2026-85575

ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution

vulnerable

Sep 15, 2026, 22:09:35
Min -
Max 4.9.6
The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates & Woo Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘shopengine_product_title_header_size’ parameter in all versions up to, and including, 4.9.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a use...

CVE-2026-89141

AI Engine

vulnerable

Sep 15, 2026, 22:09:23
Min -
Max 3.7.8
The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.7.7 via the 'mediaId' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to access and retrieve the transcribed contents of private audio attachments belonging to other users, including Administrators, via a supplied attachment ID. This...

CVE-2026-85657

Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors

vulnerable

Sep 15, 2026, 22:09:07
Min -
Max 4.16.0
The Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘profile_fields_user_email_value_prefix’ parameter in all versions up to, and including, 4.15.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user clicks on a link.

CVE-2026-15402

Event Manager, Events Calendar, Events Tickets for WooCommerce – Eventin

vulnerable

Sep 15, 2026, 22:09:01
Min -
Max 4.1.24
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'etn_shedule_objective' schedule_slot Parameter in all versions up to, and including, 4.1.23 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2026-75983

Event Manager, Events Calendar, Events Tickets for WooCommerce – Eventin

vulnerable

Sep 15, 2026, 22:09:01
Min -
Max 4.1.24
The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.1.23. This is due to the `PermissionManager::manage_permissions()` function being registered as a callback on WordPress core's `map_meta_cap` filter and unconditionally returning the always-true `'exist'` primitive for every capability check whenever the evaluated user ID is 1, without scoping this behavior to plugin-specific capabiliti...

CVE-2026-89050

Ads by WPQuads – Adsense Ads, Banner Ads, Popup Ads

vulnerable

Sep 15, 2026, 13:09:30
Min -
Max 3.0.5
The Quads Ads Manager for Google AdSense WordPress plugin before 3.0.5 does not verify payment completion with the configured payment gateway before marking an ad-selling order as paid, allowing users who can place an order to obtain a paid ad placement without payment.

CVE-2026-81742

BE REST Endpoints

vulnerable

Sep 15, 2026, 12:09:53
Min -
Max 1.0.0
The BE REST Endpoints WordPress plugin through 1.0.0 does not perform any authorization check before allowing widgets to be read, created, updated and deleted, and does not sanitize the values it stores in them, allowing unauthenticated users to inject arbitrary web scripts which will execute in the browser of any user visiting the site.