cleantalk

Vulnerabilities and Security Researches

Recent vulnerability researches

CVE/PSC Application Date Affected versions Description
Actual on: Oct 10, 2026, 21:10:25

CVE-2026-62041

WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce

vulnerable

Oct 11, 2026, 02:10:21
Min -
Max 3.4.1
Missing Authorization vulnerability in Ashok Dudhat WP Event Manager wp-event-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Event Manager: from n/a through 3.4.1.

CVE-2026-94665

Classified Listing – Classified ads & Business Directory Plugin

vulnerable

Oct 11, 2026, 02:10:07
Min -
Max 6.1.3
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mamunur Rashid Classified Listing classified-listing allows Stored XSS.This issue affects Classified Listing: from n/a through 6.1.2.

CVE-2026-94170

Social Sharing Plugin – Sassy Social Share

vulnerable

Oct 11, 2026, 02:10:03
Min -
Max 3.3.79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Heateor Support Sassy Social Share sassy-social-share allows Reflected XSS.This issue affects Sassy Social Share: from n/a through 3.3.79.

CVE-2026-96648

Data Tables Generator by Supsystic

vulnerable

Oct 11, 2026, 01:10:30
Min -
Max 1.15.3
The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Table Cell 'data' Value via updateRows Action in all versions up to, and including, 1.15.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable by Subscriber-level users when an...

CVE-2026-101324

Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder

vulnerable

Oct 11, 2026, 00:10:38
Min -
Max 6.2.15
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'any attacker-chosen name matching the {get.NAME} placeholder (PoC uses 'proof')' parameter in all versions up to, and including, 6.2.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user in...

CVE-2026-39802

Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin

vulnerable

Oct 10, 2026, 23:10:52
Min -
Max 2.3.13
Everest Backup &#8211; WordPress Cloud Backup, Migration, Restore &amp; Cloning Plugin [everest-backup] <= 2.3.13 (unfixed) CVE-2026-39802

CVE-2026-42702

Tutor LMS &#8211; eLearning and online course solution

vulnerable

Oct 10, 2026, 23:10:36
Min -
Max 4.1.1
Tutor LMS &#8211; eLearning and online course solution [tutor] < 4.1.1 CVE-2026-42702

CVE-2026-42711

Sliderby10Web

vulnerable

Oct 10, 2026, 23:10:27
Min -
Max 1.2.63
Slider by 10Web &#8211; Responsive Image Slider [slider-wd] <= 1.2.63 (unfixed) CVE-2026-42711

CVE-2026-104759

WordPress + Microsoft Office 365 / Azure AD | LOGIN

vulnerable

Oct 10, 2026, 23:10:22
Min -
Max 45.0
The WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) plugin for WordPress is vulnerable to Authentication Bypass via OIDC Nonce Replay in all versions up to, and including, 44.1 This is due to `Id_Token_Service_Deprecated::process_openidconnect_token()` using the incompatible WordPress core `wp_verify_nonce()` function to validate a nonce produced by `Nonce_Service::create_nonce()` — a 64-character hex value that `wp_verify_nonce()` can never successfully verify — causing the nonce check...

CVE-2026-96765

WordPress + Microsoft Office 365 / Azure AD | LOGIN

vulnerable

Oct 10, 2026, 23:10:22
Min -
Max 45.0
The WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id_token' parameter in all versions up to, and including, 44.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload is stored in the wpo365_errors transient for up to three days by submittin...