HTTPS redirection plugins intercept incoming requests, decide the target scheme, and issue redirects while reading proxy and forwarded headers. Easy HTTPS Redirection (SSL) version 2.0.1 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65704, confirming that the review focused on redirect target handling, settings storage, capability and nonce checks, and safe processing of proxy and forwarded headers.
Plugin Security Certification (PSC-2026-65703): ‘WP 2FA – Two-factor authentication for WordPress’ – Version 4.1.0

Two-factor authentication plugins handle login flows, generate and store shared secrets, issue one-time and backup codes, and enforce access policies across user roles. WP 2FA version 4.1.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65703, confirming that the review focused on the 2FA setup wizard, TOTP secret handling, one-time and backup code validation, capability and nonce checks on settings, and role-based enforcement.
CVE-2026-10096 – Qi Blocks – Author+ IDOR – POC

CVE-2026-10096 affects Qi Blocks through version 1.4.9 and allows authenticated Author+ users to overwrite stored styles for posts they cannot edit through the qi-blocks/v1/update-styles REST route. The endpoint trusts the supplied page_id after checking only edit_posts and publish_posts, so a user can target another author’s post. Reserved template and widget values broaden the impact to shared site surfaces, enabling persistent frontend defacement, hidden content, and degraded page usability. The issue is fixed in version 1.5.0.
Plugin Security Certification (PSC-2026-65702): “WP Crontrol” – Version 1.21.2

Cron management plugins can inspect, create, pause, delete, and immediately execute scheduled tasks that affect many parts of a WordPress site. WP Crontrol version 1.21.2 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65702. The review focused on authorization for event management, request integrity, callback and argument display, custom schedules, URL validation, bulk actions, and exported event data.
Plugin Security Certification (PSC-2026-65701): “AMP” – Version 2.5.5

AMP integrations transform WordPress output, validate generated markup, and may direct visitors between standard and optimized page variants. AMP version 2.5.5 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65701. The review focused on administrative settings, markup sanitization, validation data, template processing, component handling, and safe page delivery.
Plugin Security Certification (PSC-2026-65700): “Converter for Media – Optimize images | Convert WebP & AVIF” – Version 6.6.5

Image optimization plugins read files from the uploads directory, create alternative formats, and route visitor requests to generated assets. Converter for Media – Optimize images | Convert WebP & AVIF version 6.6.5 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65700. The review focused on source file validation, path confinement, conversion jobs, generated output, delivery rules, and permission checks around administrative actions.
Plugin Security Certification (PSC-2026-65699): “Meta Box – A Framework for Dynamic Websites” – Version 5.15.1

Custom fields frameworks render administrator-defined fields on post, term, user, and settings screens, store arbitrary meta, and expose AJAX endpoints for selecting posts, users, and terms, uploading and deleting files, and fetching oEmbeds. Meta Box – A Framework for Dynamic Websites version 5.15.1 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65699. The review focused on AJAX authorization and nonces, the file upload and delete flow, object-selection endpoints, meta storage and output escaping, and the [rwmb_meta] shortcode.
Plugin Security Certification (PSC-2026-65698): “Web Accessibility (formally known as Ally) – WCAG Scanning, Guided Fixes, Usability Widget” – Version 4.1.4

Accessibility widgets combine public front-end output with administrator-managed settings, on-page WCAG scanning, and guided fixes that change how content is presented to visitors. Web Accessibility (formally known as Ally) – WCAG Scanning, Guided Fixes, Usability Widget version 4.1.4 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65698. The review focused on REST API authorization, the public analytics endpoint, scan and remediation data handling, SVG icon uploads, and safe rendering of administrator-controlled widget settings.
Plugin Security Certification (PSC-2026-65697): “Child Theme Configurator” – Version 2.6.7

Child theme utilities inspect installed themes and can create or modify PHP, CSS, and configuration files inside the WordPress themes directory. Child Theme Configurator version 2.6.7 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65697. The review focused on administrative authorization, filesystem boundaries, theme and file selection, stylesheet parsing, template copying, and safe handling of configuration input.
Plugin Security Certification (PSC-2026-65696): “WP Mail Logging” – Version 1.16.0

Email logging plugins retain message bodies, recipient details, headers, attachments, and delivery errors that may contain sensitive operational data. WP Mail Logging version 1.16.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65696. The review focused on log access, stored message rendering, attachment references, search and bulk actions, resend requests, and protection of plugin settings.