cleantalk

Vulnerabilities and Security Researches

Recent vulnerability researches

CVE/PSC Application Date Affected versions Description
Actual on: Sep 28, 2026, 21:09:24

CVE-2026-85002

EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg

vulnerable

Sep 28, 2026, 22:09:13
Min -
Max 4.6.7
The EmbedPress WordPress plugin before 4.6.7 does not escape one of its block attributes before outputting it inside an HTML attribute, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks against higher privileged users viewing the post.

CVE-2026-96895

WP YouTube Lyte

vulnerable

Sep 28, 2026, 21:09:13
Min -
Max 1.7.31
The WP YouTube Lyte WordPress plugin before 1.7.31 does not escape some attributes of YouTube embed blocks before outputting them in an HTML attribute when rendering the block, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks.

CVE-2026-92411

WP Delicious – Best WordPress Recipes Plugin (formerly Delicious Recipes)

vulnerable

Sep 28, 2026, 15:09:06
Min -
Max 1.10.8
The WP Delicious WordPress plugin before 1.10.8 does not validate or escape the HTML tag name taken from user-supplied recipe block data before rendering it on the front end, allowing users with the Contributor role and above to inject arbitrary HTML tags, including script tags, which execute when the recipe page is viewed.

CVE-2026-19708

File Manager

vulnerable

Sep 28, 2026, 06:09:23
Min 7.2.2
Max 8.0.5
The File Manager WordPress plugin before 8.0.5 does not prevent unauthenticated users from downloading its database backup archives, and in some cases writes them under a fixed filename, allowing unauthenticated attackers to retrieve a full database dump including every user's email address and password hash on servers that do not apply the directory's .htaccess file.

CVE-2026-85081

File Manager

vulnerable

Sep 28, 2026, 06:09:23
Min -
Max 8.0.5
The File Manager WordPress plugin before 8.0.5, FileOrganizer WordPress plugin before 1.2.1, File Manager Pro WordPress plugin before 2.1.3 do not correctly validate the origin of window messages received by the file browser they load on their admin screens, accepting any origin that is a leading string prefix of the site's own address, which allows an unauthenticated attacker to run arbitrary JavaScript in the session of a logged-in administrator who visits a page under their control. The defect is in t...

CVE-2026-89237

Bluff Post

vulnerable

Sep 28, 2026, 05:09:31
Min -
Max 1.1.1
The Bluff Post WordPress plugin through 1.1.1 does not sanitise and escape parameters before using them as identifiers in a SQL query, allowing unauthenticated attackers to append additional SQL and extract sensitive information from the database.

CVE-2026-11871

Team Member – Multi Language Supported Team Plugin

vulnerable

Sep 28, 2026, 05:09:26
Min -
Max 9.2
The Team Members WordPress plugin through 9.2 does not perform any authorization or visibility check in an unauthenticated AJAX action that returns full team member records by ID, allowing unauthenticated attackers to enumerate and disclose details, including email addresses and phone numbers, of team members the administrator has not published publicly.

CVE-2025-0818

File Manager Pro – Filester

vulnerable

Sep 28, 2026, 04:09:28
Min -
Max 1.9
Several WordPress plugins using elFinder versions 2.1.64 and prior are vulnerable to Directory Traversal in various versions. This makes it possible for unauthenticated attackers to delete arbitrary files. Successful exploitation of this vulnerability requires a site owner to explicitly make an instance of the file manager available to users.

CVE-2026-85081

File Manager Pro – Filester

vulnerable

Sep 28, 2026, 04:09:28
Min -
Max 2.1.3
The File Manager WordPress plugin before 8.0.5, FileOrganizer WordPress plugin before 1.2.1, File Manager Pro WordPress plugin before 2.1.3 do not correctly validate the origin of window messages received by the file browser they load on their admin screens, accepting any origin that is a leading string prefix of the site's own address, which allows an unauthenticated attacker to run arbitrary JavaScript in the session of a logged-in administrator who visits a page under their control. The defect is in t...

CVE-2026-96531

Image Optimization by Optimole – Lazy Load, CDN, Convert WebP & AVIF

vulnerable

Sep 28, 2026, 03:09:14
Min 4.0.0
Max 4.2.13
The Optimole WordPress plugin before 4.2.13 does not escape unrecognized attributes of its video-player block before rendering them onto the block's wrapper element, allowing users with the Author role and above to store an event-handler attribute that executes scripts in the browser of any user, such as an administrator, who views the post.