cleantalk

Vulnerabilities and Security Researches

Recent vulnerability researches

CVE/PSC Application Date Affected versions Description
Actual on: Sep 25, 2026, 18:09:38

CVE-2026-75799

YAHMAN Add-ons

vulnerable

Sep 25, 2026, 21:09:31
Min -
Max 0.9.31
The YAHMAN Add-ons WordPress plugin before 0.9.31 does not validate the type of the remote files it caches in a publicly accessible directory, allowing unauthenticated attackers to write arbitrary PHP files on the server and achieve RCE when the relevant feature is enabled.

CVE-2026-93899

Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss

vulnerable

Sep 25, 2026, 20:09:56
Min -
Max 3.0.5
The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to generic SQL Injection via 'group_id' Message Meta Parameter in all versions up to, and including, 3.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be use...

CVE-2026-94376

Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss

vulnerable

Sep 25, 2026, 20:09:56
Min -
Max 3.0.5
The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via User Display Name in all versions up to, and including, 3.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable by Subscriber-leve...

CVE-2026-93897

GeoDirectory – WordPress Business Directory Plugin, or Classified Directory

vulnerable

Sep 25, 2026, 20:09:32
Min -
Max 2.8.182
The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Text-type Custom Field (e.g., 'phone') in all versions up to, and including, 2.8.181 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload must be s...

CVE-2026-96766

GeoDirectory – WordPress Business Directory Plugin, or Classified Directory

vulnerable

Sep 25, 2026, 20:09:32
Min -
Max 2.8.184
The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'business_hours' parameter in all versions up to, and including, 2.8.183 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is possible because the ...

CVE-2026-93656

User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor

vulnerable

Sep 25, 2026, 20:09:30
Min -
Max 4.0.3
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Avatar Field in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable via a nonce-free...

CVE-2026-95866

User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor

vulnerable

Sep 25, 2026, 20:09:30
Min -
Max 4.0.3
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Avatar Field in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The zero-length multipart file branch in wppb_save_avatar_value() writes th...

CVE-2026-93662

Events Manager – Calendar, Bookings, Tickets, and more!

vulnerable

Sep 25, 2026, 20:09:01
Min 7.4.1
Max 7.4.5
The Events Manager WordPress plugin before 7.4.5 does not force the scope of its logged-in event and location search when a caller supplies their own owner value, letting a low-privileged user read other accounts' unpublished, pending or trashed event and venue content, including full street addresses.

CVE-2026-93661

Events Manager – Calendar, Bookings, Tickets, and more!

vulnerable

Sep 25, 2026, 20:09:01
Min -
Max 7.4.5
The Events Manager WordPress plugin before 7.4.5 does not stop a ticket-update request from replacing the identifiers of the ticket it was authorized against, letting a user who can manage one event's tickets overwrite and reassign any ticket on the site to their own event.

CVE-2026-12037

Asset CleanUp: Page Speed Booster

vulnerable

Sep 25, 2026, 19:09:55
Min -
Max 1.4.0.6
The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.4.0.5 via the 'page_url' parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. This vulnerability is only reachable when the plugin's dom_get_type setting has been...

Recent approved applications

Application Date Description Details
Actual on: Sep 25, 2026, 18:09:38

Disable XML-RPC

Sep 25, 2026, 12:09:44 XML-RPC controls affect remote publishing clients and other integrations that communicate with WordPress through the XML-RPC endpoint. Disable XML-RPC version 1.0.1 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65709. The review focused on plugin bootstrap behavior, filter registration, XML-RPC availability, activation state, compatibility with the WordPress request path, and the absence of unnecessary user input surfaces.

Widget Importer & Exporter

Sep 25, 2026, 12:09:44 Widget migration tools process configuration data that can create or update active and inactive widget instances across a WordPress site. Widget Importer & Exporter version 1.6.1 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65707. The review focused on upload handling, JSON data validation, administrator permissions, widget instance import, export output, duplicate detection, unsupported widgets, and developer hooks.

Instant Indexing for Google

Sep 25, 2026, 12:09:44 Search submission plugins handle site URLs and service credentials while sending manual or automatic requests to external indexing endpoints. Instant Indexing for Google version 1.1.22 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65710. The review focused on settings permissions, credential handling, URL validation, manual and bulk submissions, automatic post events, remote API requests, response output, post type exclusions, and IndexNow controls.

Simple Cloudflare Turnstile – CAPTCHA Alternative

Sep 25, 2026, 12:09:44 Anti-spam integrations accept challenge tokens on public forms and exchange them with an external verification service before a submission is allowed. Simple CAPTCHA with Cloudflare Turnstile version 1.43.2 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65708. The review focused on settings permissions, key handling, challenge token validation, server side verification, form integration, whitelisting, failsafe behavior, and diagnostic logging.

AMP

Sep 22, 2026, 11:09:27 AMP integrations transform WordPress output, validate generated markup, and may direct visitors between standard and optimized page variants. AMP version 2.5.5 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65701. The review focused on administrative settings, markup sanitization, validation data, template processing, component handling, and safe page delivery.

Converter for Media – Optimize images | Convert WebP & AVIF

Sep 22, 2026, 11:09:27 Image optimization plugins read files from the uploads directory, create alternative formats, and route visitor requests to generated assets. Converter for Media - Optimize images | Convert WebP & AVIF version 6.6.5 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65700. The review focused on source file validation, path confinement, conversion jobs, generated output, delivery rules, and permission checks around administrative actions.

WP Crontrol

Sep 22, 2026, 11:09:27 Cron management plugins can inspect, create, pause, delete, and immediately execute scheduled tasks that affect many parts of a WordPress site. WP Crontrol version 1.21.2 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65702. The review focused on authorization for event management, request integrity, callback and argument display, custom schedules, URL validation, bulk actions, and exported event data.

Child Theme Configurator

Sep 18, 2026, 11:09:14 Child theme utilities inspect installed themes and can create or modify PHP, CSS, and configuration files inside the WordPress themes directory. Child Theme Configurator version 2.6.7 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65697. The review focused on administrative authorization, filesystem boundaries, theme and file selection, stylesheet parsing, template copying, and safe handling of configuration input.

WP Mail Logging

Sep 18, 2026, 11:09:14 Email logging plugins retain message bodies, recipient details, headers, attachments, and delivery errors that may contain sensitive operational data. WP Mail Logging version 1.16.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65696. The review focused on log access, stored message rendering, attachment references, search and bulk actions, resend requests, and protection of plugin settings.

Health Check & Troubleshooting

Aug 25, 2026, 23:08:42 Diagnostic plugins inspect server and WordPress configuration, collect debug data, verify files and email delivery, and alter plugin or theme state for a troubleshooting session. Health Check & Troubleshooting version 1.7.1 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64692, confirming that the review focused on privileged diagnostics, session isolation, debug data disclosure, file integrity checks, tool requests, and temporary troubleshooting controls...