cleantalk

Vulnerabilities and Security Researches

Recent vulnerability researches

CVE/PSC Application Date Affected versions Description
Actual on: Sep 13, 2026, 05:09:12

CVE-2026-62110

Bold Page Builder

vulnerable

Sep 13, 2026, 10:09:12
Min -
Max 5.9.10
Contributor Cross Site Scripting (XSS) in Bold Page Builder <= 5.9.9 versions.

CVE-2026-62134

Starter Templates — Elementor, WordPress &amp; Beaver Builder Templates

vulnerable

Sep 13, 2026, 09:09:47
Min -
Max 4.7.6
Contributor Insecure Direct Object References (IDOR) in Starter Templates <= 4.7.5 versions.

CVE-2026-86809

Persian Elementor

vulnerable

Sep 13, 2026, 09:09:43
Min -
Max 2.8.2
The Persian Elementor WordPress plugin from 2.7.10 before 2.8.2 does not verify that the payment authority returned to its ZarinPal payment callback belongs to the transaction being completed, allowing unauthenticated attackers to complete a pending order using a valid payment authority obtained from a different transaction.

CVE-2026-62138

Visual Composer Website Builder, Landing Page Builder, Custom Theme Builder, Maintenance Mode &amp; Coming Soon Pages

vulnerable

Sep 13, 2026, 09:09:38
Min -
Max 45.16.2
Contributor Cross Site Scripting (XSS) in Visual Composer Website Builder <= 45.16.1 versions.

CVE-2026-62106

SMS Alert Order Notifications &#8211; WooCommerce

vulnerable

Sep 13, 2026, 09:09:11
Min -
Max 4.0.0
Subscriber Privilege Escalation in SMS Alert Order Notifications <= 3.9.9 versions.

CVE-2026-62113

Slim SEO &#8211; Fast &amp; Automated WordPress SEO Plugin

vulnerable

Sep 13, 2026, 08:09:49
Min -
Max 4.10.1
Contributor Insecure Direct Object References (IDOR) in Slim SEO <= 4.10.0 versions.

CVE-2026-62140

Quiz And Survey Master &#8211; Best Quiz, Exam and Survey Plugin for WordPress

vulnerable

Sep 13, 2026, 07:09:52
Min -
Max 11.2.6
Unauthenticated Insecure Direct Object References (IDOR) in Quiz And Survey Master <= 11.2.5 versions.

CVE-2026-16482

rtMedia for WordPress, BuddyPress and bbPress

vulnerable

Sep 13, 2026, 07:09:47
Min -
Max 4.7.12
The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'compare' parameter in all versions up to, and including, 4.7.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This is explo...

CVE-2025-15695

Translate WordPress with GTranslate

vulnerable

Sep 13, 2026, 07:09:26
Min -
Max 3.0.10
The Translate WordPress with GTranslate WordPress plugin before 3.0.10 does not validate one of its settings before the bundled front-end scripts build markup from it, allowing users with a role as high as administrator to store JavaScript that runs in the session of any visitor to the site.

CVE-2026-86813

Metform Elementor Contact Form Builder

vulnerable

Sep 13, 2026, 07:09:26
Min -
Max 4.1.9
The MetForm WordPress plugin before 4.1.9 does not properly neutralize newline characters in user-submitted values that are placed into notification email headers, allowing unauthenticated attackers to inject additional email headers, such as Bcc, into the emails the site sends when a submitted field value is configured to populate a header.

Recent approved applications

Application Date Description Details
Actual on: Sep 13, 2026, 05:09:12

Health Check & Troubleshooting

Aug 25, 2026, 23:08:42 Diagnostic plugins inspect server and WordPress configuration, collect debug data, verify files and email delivery, and alter plugin or theme state for a troubleshooting session. Health Check & Troubleshooting version 1.7.1 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64692, confirming that the review focused on privileged diagnostics, session isolation, debug data disclosure, file integrity checks, tool requests, and temporary troubleshooting controls...

Limit Login Attempts

Aug 25, 2026, 23:08:42 Login protection plugins operate directly on authentication requests, retry counters, lockouts, cookies, client addresses, and administrative notifications. Limit Login Attempts version 1.7.2 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64690, confirming that the review focused on retry tracking, IP handling, lockout enforcement, authentication cookie checks, configuration access, and safe logging of failed attempts.

Force Regenerate Thumbnails

Aug 25, 2026, 23:08:42 Thumbnail regeneration tools delete derived image sizes, read original uploads, create replacement files, and execute batch operations across the media library. Force Regenerate Thumbnails version 2.3.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64694, confirming that the review focused on attachment authorization, path confinement, batch requests, file deletion scope, image processing inputs, and progress handling.

Advanced Google reCAPTCHA

Aug 25, 2026, 23:08:42 CAPTCHA integrations sit on public login, registration, password reset, comment, commerce, and community forms where untrusted requests meet account and content workflows. Advanced Google reCAPTCHA version 5.40 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64693, confirming that the review focused on token verification, protected form coverage, settings authorization, remote API handling, bypass resistance, and safe failure behavior.

Complianz &#8211; Terms and Conditions

Aug 25, 2026, 23:08:42 Legal document generators collect business and website details, store wizard answers, publish generated pages, and may process consumer withdrawal submissions. Complianz - Terms and Conditions version 1.4.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64691, confirming that the review focused on wizard permissions, stored configuration, document output, withdrawal form requests, email handling, anti-abuse controls, and safe rendering of generated text.

Disable Comments &#8211; Remove Comments &amp; Stop Spam [Multi-Site Support]

Aug 25, 2026, 00:08:21 Comment management tools affect public submission paths, administration screens, feeds, APIs, and multisite policy. Disable Comments - Remove Comments & Stop Spam [Multi-Site Support] version 2.8.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64686, confirming that the review focused on settings access, request validation, comment-related endpoints, role-aware controls, and consistent enforcement across supported site contexts.

Admin Menu Editor

Aug 25, 2026, 00:08:21 Dashboard customization tools influence navigation, capability checks, menu visibility, redirects, and access to administrative screens. Admin Menu Editor version 1.15.2 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64688, confirming that the review focused on settings authorization, capability handling, menu configuration integrity, redirect behavior, and safe processing of custom labels, URLs, and icons.

WebP Express

Aug 25, 2026, 00:08:21 Image conversion plugins process uploaded files, write derivatives, update rewrite rules, and may invoke local or remote converters. WebP Express version 0.25.15 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64689, confirming that the review focused on file access, conversion inputs, generated output paths, rewrite behavior, converter configuration, and protection of privileged settings.

Premium Addons for Elementor

Jul 28, 2026, 10:07:24 Elementor extension packs add widgets, templates, display rules, and dynamic output to the page builder. Because saved widget settings become public HTML, secure rendering and protected editor actions are essential. Premium Addons for Elementor - Powerful Elementor Templates & Widgets version 4.11.89 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64677, confirming that the plugin was reviewed from a secure code perspective with attention to widget config...

Template Kit &#8211; Import

Jul 28, 2026, 10:07:24 Template import tools bring structured design data and assets into a WordPress installation. Import permissions, file validation, remote resources, and the safety of stored page content all matter before an imported kit reaches the public site. Template Kit - Import version 1.0.16 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64682, confirming that the plugin was reviewed from a secure code perspective with attention to import authorization, package val...