cleantalk

Vulnerabilities and Security Researches

Recent vulnerability researches

CVE/PSC Application Date Affected versions Description
Actual on: Aug 21, 2026, 02:08:28

CVE-2026-73362

URL Shortify – Simple, Powerful and Easy URL Shortener Plugin For WordPress

vulnerable

Aug 21, 2026, 06:08:30
Min -
Max 2.5.1
Unauthenticated Cross Site Scripting (XSS) in URL Shortify <= 2.5.0 versions.

CVE-2026-73398

Piraeus Bank WooCommerce Payment Gateway

vulnerable

Aug 21, 2026, 05:08:46
Min -
Max 3.2.0
Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions.

CVE-2026-14826

Quiz And Survey Master &#8211; Best Quiz, Exam and Survey Plugin for WordPress

vulnerable

Aug 21, 2026, 05:08:38
Min -
Max 11.2.4
The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check on the REST routes that return a quiz's email-notification and results-page configuration, allowing users with contributor-level access and above to read the configuration, including notification recipient addresses, of quizzes created by other users.

CVE-2026-14825

Quiz And Survey Master &#8211; Best Quiz, Exam and Survey Plugin for WordPress

vulnerable

Aug 21, 2026, 05:08:38
Min -
Max 11.2.4
The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check before saving a quiz's front-end text settings, allowing users with contributor-level access and above to modify the text settings of quizzes created by other users.

CVE-2026-68568

MasterStudy LMS WordPress Plugin – for Online Courses and Education

vulnerable

Aug 21, 2026, 05:08:36
Min -
Max 3.7.42
Subscriber Privilege Escalation in MasterStudy LMS <= 3.7.41 versions.

CVE-2026-73404

MasterStudy LMS WordPress Plugin – for Online Courses and Education

vulnerable

Aug 21, 2026, 05:08:36
Min -
Max 3.7.42
Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 versions.

CVE-2026-73350

SupportCandy &#8211; Helpdesk &amp; Customer Support Ticket System

vulnerable

Aug 21, 2026, 04:08:25
Min -
Max 3.5.2
Unauthenticated Broken Authentication in SupportCandy <= 3.5.1 versions.

CVE-2026-74006

WP Table Builder &#8211; WordPress Table Plugin

vulnerable

Aug 21, 2026, 04:08:17
Min -
Max 2.2.0
Contributor Broken Access Control in WP Table Builder <= 2.2.0 versions.

CVE-2026-73377

Ultimate Maps by Supsystic

vulnerable

Aug 21, 2026, 03:08:58
Min -
Max 1.5.0
Unauthenticated Broken Access Control in Ultimate Maps by Supsystic < 1.5.0 versions.

CVE-2026-73375

Ultimate Maps by Supsystic

vulnerable

Aug 21, 2026, 03:08:58
Min -
Max 1.5.0
Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic < 1.5.0 versions.

Recent approved applications

Application Date Description Details
Actual on: Aug 21, 2026, 02:08:28

LiteSpeed Cache

Jul 28, 2026, 10:07:24 Caching and optimization plugins sit directly in the path that produces a public page. Their settings can influence stored output, asset delivery, and the content returned to every visitor. LiteSpeed Cache version 7.8.1 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64675, confirming that the plugin was reviewed from a secure code perspective with attention to cache isolation, purge controls, generated assets, optimization requests, and privileged settin...

Smush &#8211; Optimize, Compress and Lazy Load Images

Jul 28, 2026, 10:07:24 Image optimization plugins process files that become part of nearly every public page. Compression, format conversion, lazy loading, and CDN delivery all need careful handling of uploads, metadata, and generated URLs. Smush - Image Optimization, Compression, Lazy Load, WebP & CDN version 4.2.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64676, confirming that the plugin was reviewed from a secure code perspective with attention to image processing inp...

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress

Jul 28, 2026, 10:07:24 Form builders accept untrusted input from public visitors and turn it into stored records, notifications, and administrator workflows. Secure validation, permission checks, and careful output handling are central to every submission path. Ninja Forms - The Contact Form Builder That Grows With You version 3.14.11 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64678, confirming that the plugin was reviewed from a secure code perspective with attention to p...

Premium Addons for Elementor

Jul 28, 2026, 10:07:24 Elementor extension packs add widgets, templates, display rules, and dynamic output to the page builder. Because saved widget settings become public HTML, secure rendering and protected editor actions are essential. Premium Addons for Elementor - Powerful Elementor Templates & Widgets version 4.11.89 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64677, confirming that the plugin was reviewed from a secure code perspective with attention to widget config...

Template Kit &#8211; Import

Jul 28, 2026, 10:07:24 Template import tools bring structured design data and assets into a WordPress installation. Import permissions, file validation, remote resources, and the safety of stored page content all matter before an imported kit reaches the public site. Template Kit - Import version 1.0.16 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64682, confirming that the plugin was reviewed from a secure code perspective with attention to import authorization, package val...

Intuitive Custom Post Order

Jul 28, 2026, 10:07:24 Content ordering plugins turn drag-and-drop administrator actions into persistent changes across posts, pages, taxonomies, and sites. Those updates must be limited to authorized objects and protected from forged requests. Intuitive Custom Post Order version 3.2.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64683, confirming that the plugin was reviewed from a secure code perspective with attention to reorder permissions, request integrity, object iden...

Honeypot for Contact Form 7

Jul 28, 2026, 10:07:24 Contact Form 7 extensions can influence spam checks, stored submissions, redirects, and outbound webhooks. These features cross the boundary between anonymous form input, privileged records, external destinations, and front-end responses. CF7 Apps - Honeypot, Database, Redirection, Webhook, and Addons for Contact Form 7 version 3.6.1 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64684, confirming that the plugin was reviewed from a secure code perspecti...

WooCommerce Legacy REST API

Jul 28, 2026, 10:07:24 Commerce APIs expose structured access to products, orders, customers, and store operations. A compatibility plugin that restores legacy endpoints must enforce authentication and permissions consistently across every request. WooCommerce Legacy REST API version 1.0.5 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64680, confirming that the plugin was reviewed from a secure code perspective with attention to API authentication, request authorization, obje...

Jetpack – WP Security, Backup, Speed, & Growth

Jun 25, 2026, 16:06:39 Security and performance suites operate across many areas of a WordPress installation, including backups, malware scanning, content delivery, statistics, forms, and social publishing. That makes them operationally useful, but also security-sensitive because a broad plugin footprint can affect privileged settings, connected service tokens, public scripts, and administrator workflows. Jetpack - WP Security, Backup, Speed, and Growth version 15.9.1 has successfully completed the CleanTalk Plugin Security Certi...

Admin and Site Enhancements (ASE)

Jun 25, 2026, 16:06:39 Administrative enhancement plugins concentrate many privileged controls in one interface, including editor behavior, media tools, SMTP settings, menu changes, and site management modules. That makes them efficient for administrators, but also security-sensitive because broad settings can affect core WordPress behavior. Admin and Site Enhancements (ASE) version 8.8.5 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64673, confirming that the plugin was revi...