cleantalk

Vulnerabilities and Security Researches

Recent vulnerability researches

CVE/PSC Application Date Affected versions Description
Actual on: Aug 18, 2026, 13:08:47

CVE-2026-14498

Query Wrangler

vulnerable

Aug 18, 2026, 14:08:36
Min -
Max 1.5.58
The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5.57 via the 'options' parameter parameter. This is due to missing capability check and nonce verification on the wp_ajax_qw_form_ajax handler, combined with unsanitized attacker-controlled options fully replacing saved query options and being passed directly to call_user_func_array() guarded only by function_exists(). This makes it possible for authenticated attackers, with subscriber-leve...

CVE-2026-14524

ProSolution WP Client

vulnerable

Aug 18, 2026, 14:08:23
Min -
Max 2.0.9
The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the proSol_fileDeleteProcess function in all versions up to, and including, 2.0.8. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). An attacker must first call the proSol_fileUploadModalProcess handler to poison their own session wi...

CVE-2026-16098

ProSolution WP Client

vulnerable

Aug 18, 2026, 14:08:23
Min -
Max 2.0.11
The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.0.10 via the proSol_handleFileUpload function. This is due to missing validation of the attacker-controlled Content-Disposition header filename, which overrides the allow-listed multipart filename before the file is saved, and a post-save extension check that fails to delete the already-written file. This makes it possible for unauthenticated attackers to upload files that may be exe...

CVE-2026-18807

Elementor Custom Skin

vulnerable

Aug 18, 2026, 14:08:20
Min -
Max 4.3.8
The ECS WordPress plugin before 4.3.8 does not have capability or ownership checks on its dynamic repeater actions, relying only on a nonce available to any user who can open the page builder, allowing users with a contributor-level account or above to read, alter and delete the binding configuration of posts they do not own and to change the ECS WordPress plugin before 4.3.8's site-wide presets.

CVE-2026-14230

Elementor Custom Skin

vulnerable

Aug 18, 2026, 14:08:20
Min -
Max 4.3.8
The ECS WordPress plugin before 4.3.8 does not perform capability or object-ownership checks on its Dynamic Repeater AJAX handlers (gated only by a capability-agnostic nonce that any edit_posts user obtains from the Elementor editor), so a Contributor can write a data-source binding into any post — including admin-authored pages — whose attacker-controlled values are rendered into a widget's repeater output without sanitization, executing JavaScript in the session of any visitor or administrator who views ...

CVE-2026-19613

Elementor Custom Skin

vulnerable

Aug 18, 2026, 14:08:20
Min -
Max 4.3.10
The ECS WordPress plugin before 4.3.10 does not perform ownership or post-status checks when one of its dynamic repeater data sources reads custom field values from a user-supplied post identifier, allowing users with a contributor-level account or above to read custom field values and post metadata from posts they do not own, including private and draft ones.

CVE-2026-14229

Elementor Custom Skin

vulnerable

Aug 18, 2026, 14:08:20
Min -
Max 4.3.8
The ECS WordPress plugin before 4.3.8 does not check the post status or any capability when rendering an Elementor document requested through one of its AJAX actions, allowing unauthenticated users to retrieve the rendered content of unpublished (private, draft, pending) documents by supplying their identifier.

CVE-2026-16775

Smash Balloon Social Post Feed

vulnerable

Aug 18, 2026, 14:08:15
Min -
Max 4.10.0
The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'id' Shortcode Attribute in all versions up to, and including, 4.9.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2026-15345

ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization

vulnerable

Aug 18, 2026, 14:08:04
Min -
Max 3.11.6
The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.11.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify configuration options of third-party plugins including ShortPixel Image Optimizer, Autoptimize, WP Rocket, Imagify, and LiteSpeed Cache, as...

CVE-2026-2487

Admin Custom Login

vulnerable

Aug 18, 2026, 13:08:54
Min -
Max 3.6.5
The Admin Custom Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabl...

Recent approved applications

Application Date Description Details
Actual on: Aug 18, 2026, 13:08:47

LiteSpeed Cache

Jul 28, 2026, 10:07:24 Caching and optimization plugins sit directly in the path that produces a public page. Their settings can influence stored output, asset delivery, and the content returned to every visitor. LiteSpeed Cache version 7.8.1 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64675, confirming that the plugin was reviewed from a secure code perspective with attention to cache isolation, purge controls, generated assets, optimization requests, and privileged settin...

Smush – Optimize, Compress and Lazy Load Images

Jul 28, 2026, 10:07:24 Image optimization plugins process files that become part of nearly every public page. Compression, format conversion, lazy loading, and CDN delivery all need careful handling of uploads, metadata, and generated URLs. Smush - Image Optimization, Compression, Lazy Load, WebP & CDN version 4.2.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64676, confirming that the plugin was reviewed from a secure code perspective with attention to image processing inp...

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress

Jul 28, 2026, 10:07:24 Form builders accept untrusted input from public visitors and turn it into stored records, notifications, and administrator workflows. Secure validation, permission checks, and careful output handling are central to every submission path. Ninja Forms - The Contact Form Builder That Grows With You version 3.14.11 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64678, confirming that the plugin was reviewed from a secure code perspective with attention to p...

Premium Addons for Elementor

Jul 28, 2026, 10:07:24 Elementor extension packs add widgets, templates, display rules, and dynamic output to the page builder. Because saved widget settings become public HTML, secure rendering and protected editor actions are essential. Premium Addons for Elementor - Powerful Elementor Templates & Widgets version 4.11.89 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64677, confirming that the plugin was reviewed from a secure code perspective with attention to widget config...

Template Kit – Import

Jul 28, 2026, 10:07:24 Template import tools bring structured design data and assets into a WordPress installation. Import permissions, file validation, remote resources, and the safety of stored page content all matter before an imported kit reaches the public site. Template Kit - Import version 1.0.16 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64682, confirming that the plugin was reviewed from a secure code perspective with attention to import authorization, package val...

Intuitive Custom Post Order

Jul 28, 2026, 10:07:24 Content ordering plugins turn drag-and-drop administrator actions into persistent changes across posts, pages, taxonomies, and sites. Those updates must be limited to authorized objects and protected from forged requests. Intuitive Custom Post Order version 3.2.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64683, confirming that the plugin was reviewed from a secure code perspective with attention to reorder permissions, request integrity, object iden...

Honeypot for Contact Form 7

Jul 28, 2026, 10:07:24 Contact Form 7 extensions can influence spam checks, stored submissions, redirects, and outbound webhooks. These features cross the boundary between anonymous form input, privileged records, external destinations, and front-end responses. CF7 Apps - Honeypot, Database, Redirection, Webhook, and Addons for Contact Form 7 version 3.6.1 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64684, confirming that the plugin was reviewed from a secure code perspecti...

WooCommerce Legacy REST API

Jul 28, 2026, 10:07:24 Commerce APIs expose structured access to products, orders, customers, and store operations. A compatibility plugin that restores legacy endpoints must enforce authentication and permissions consistently across every request. WooCommerce Legacy REST API version 1.0.5 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64680, confirming that the plugin was reviewed from a secure code perspective with attention to API authentication, request authorization, obje...

Jetpack – WP Security, Backup, Speed, & Growth

Jun 25, 2026, 16:06:39 Security and performance suites operate across many areas of a WordPress installation, including backups, malware scanning, content delivery, statistics, forms, and social publishing. That makes them operationally useful, but also security-sensitive because a broad plugin footprint can affect privileged settings, connected service tokens, public scripts, and administrator workflows. Jetpack - WP Security, Backup, Speed, and Growth version 15.9.1 has successfully completed the CleanTalk Plugin Security Certi...

Admin and Site Enhancements (ASE)

Jun 25, 2026, 16:06:39 Administrative enhancement plugins concentrate many privileged controls in one interface, including editor behavior, media tools, SMTP settings, menu changes, and site management modules. That makes them efficient for administrators, but also security-sensitive because broad settings can affect core WordPress behavior. Admin and Site Enhancements (ASE) version 8.8.5 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64673, confirming that the plugin was revi...