Search submission plugins handle site URLs and service credentials while sending manual or automatic requests to external indexing endpoints. Instant Indexing for Google version 1.1.22 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65710. The review focused on settings permissions, credential handling, URL validation, manual and bulk submissions, automatic post events, remote API requests, response output, post type exclusions, and IndexNow controls.
Plugin Security Certification (PSC-2026-65709): “Disable XML-RPC” – Version 1.0.1

XML-RPC controls affect remote publishing clients and other integrations that communicate with WordPress through the XML-RPC endpoint. Disable XML-RPC version 1.0.1 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65709. The review focused on plugin bootstrap behavior, filter registration, XML-RPC availability, activation state, compatibility with the WordPress request path, and the absence of unnecessary user input surfaces.
Plugin Security Certification (PSC-2026-65708): “Simple CAPTCHA with Cloudflare Turnstile” – Version 1.43.2

Anti-spam integrations accept challenge tokens on public forms and exchange them with an external verification service before a submission is allowed. Simple CAPTCHA with Cloudflare Turnstile version 1.43.2 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65708. The review focused on settings permissions, key handling, challenge token validation, server side verification, form integration, whitelisting, failsafe behavior, and diagnostic logging.
Plugin Security Certification (PSC-2026-65707): “Widget Importer & Exporter” – Version 1.6.1

Widget migration tools process configuration data that can create or update active and inactive widget instances across a WordPress site. Widget Importer & Exporter version 1.6.1 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65707. The review focused on upload handling, JSON data validation, administrator permissions, widget instance import, export output, duplicate detection, unsupported widgets, and developer hooks.
Plugin Security Certification (PSC-2026-65705): ‘Presto Player’ – Version 4.5.1

Media player plugins embed and stream video and audio, render player markup on the front end, store per-media settings, and expose REST and AJAX endpoints for playback data and analytics. Presto Player version 4.5.1 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65705, confirming that the review focused on media block rendering and output escaping, REST and AJAX endpoint authorization, settings storage, and handling of external video sources and uploaded media.
Plugin Security Certification (PSC-2026-65706): ‘YITH WooCommerce Compare’ – Version 3.14.0

Product comparison plugins add and remove items through AJAX, store the visitor’s comparison list, and render a table of product attributes on the front end. YITH WooCommerce Compare version 3.14.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65706, confirming that the review focused on the AJAX add/remove endpoints, product ID handling, output escaping in the comparison table, and sanitization of the plugin’s settings.
Plugin Security Certification (PSC-2026-65704): ‘Easy HTTPS Redirection (SSL)’ – Version 2.0.1

HTTPS redirection plugins intercept incoming requests, decide the target scheme, and issue redirects while reading proxy and forwarded headers. Easy HTTPS Redirection (SSL) version 2.0.1 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65704, confirming that the review focused on redirect target handling, settings storage, capability and nonce checks, and safe processing of proxy and forwarded headers.
Plugin Security Certification (PSC-2026-65703): ‘WP 2FA – Two-factor authentication for WordPress’ – Version 4.1.0

Two-factor authentication plugins handle login flows, generate and store shared secrets, issue one-time and backup codes, and enforce access policies across user roles. WP 2FA version 4.1.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65703, confirming that the review focused on the 2FA setup wizard, TOTP secret handling, one-time and backup code validation, capability and nonce checks on settings, and role-based enforcement.
CVE-2026-10096 – Qi Blocks – Author+ IDOR – POC

CVE-2026-10096 affects Qi Blocks through version 1.4.9 and allows authenticated Author+ users to overwrite stored styles for posts they cannot edit through the qi-blocks/v1/update-styles REST route. The endpoint trusts the supplied page_id after checking only edit_posts and publish_posts, so a user can target another author’s post. Reserved template and widget values broaden the impact to shared site surfaces, enabling persistent frontend defacement, hidden content, and degraded page usability. The issue is fixed in version 1.5.0.
Plugin Security Certification (PSC-2026-65702): “WP Crontrol” – Version 1.21.2

Cron management plugins can inspect, create, pause, delete, and immediately execute scheduled tasks that affect many parts of a WordPress site. WP Crontrol version 1.21.2 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65702. The review focused on authorization for event management, request integrity, callback and argument display, custom schedules, URL validation, bulk actions, and exported event data.