CVE-2026-10096 – Qi Blocks – Author+ IDOR – POC

CVE-2026-10096 – Qi Blocks – Author+ IDOR – POC

CVE-2026-10096 affects Qi Blocks through version 1.4.9 and allows authenticated Author+ users to overwrite stored styles for posts they cannot edit through the qi-blocks/v1/update-styles REST route. The endpoint trusts the supplied page_id after checking only edit_posts and publish_posts, so a user can target another author’s post. Reserved template and widget values broaden the impact to shared site surfaces, enabling persistent frontend defacement, hidden content, and degraded page usability. The issue is fixed in version 1.5.0.

Plugin Security Certification (PSC-2026-65702): “WP Crontrol” – Version 1.21.2

Plugin Security Certification (PSC-2026-65702): “WP Crontrol” – Version 1.21.2

Cron management plugins can inspect, create, pause, delete, and immediately execute scheduled tasks that affect many parts of a WordPress site. WP Crontrol version 1.21.2 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65702. The review focused on authorization for event management, request integrity, callback and argument display, custom schedules, URL validation, bulk actions, and exported event data.

Plugin Security Certification (PSC-2026-65701): “AMP” – Version 2.5.5

Plugin Security Certification (PSC-2026-65701): “AMP” – Version 2.5.5

AMP integrations transform WordPress output, validate generated markup, and may direct visitors between standard and optimized page variants. AMP version 2.5.5 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65701. The review focused on administrative settings, markup sanitization, validation data, template processing, component handling, and safe page delivery.

Plugin Security Certification (PSC-2026-65700): “Converter for Media – Optimize images | Convert WebP & AVIF” – Version 6.6.5

Plugin Security Certification (PSC-2026-65700): “Converter for Media – Optimize images | Convert WebP & AVIF” – Version 6.6.5

Image optimization plugins read files from the uploads directory, create alternative formats, and route visitor requests to generated assets. Converter for Media – Optimize images | Convert WebP & AVIF version 6.6.5 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65700. The review focused on source file validation, path confinement, conversion jobs, generated output, delivery rules, and permission checks around administrative actions.

Plugin Security Certification (PSC-2026-65699): “Meta Box – A Framework for Dynamic Websites” – Version 5.15.1

Plugin Security Certification (PSC-2026-65699): “Meta Box – A Framework for Dynamic Websites” – Version 5.15.1

Custom fields frameworks render administrator-defined fields on post, term, user, and settings screens, store arbitrary meta, and expose AJAX endpoints for selecting posts, users, and terms, uploading and deleting files, and fetching oEmbeds. Meta Box – A Framework for Dynamic Websites version 5.15.1 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65699. The review focused on AJAX authorization and nonces, the file upload and delete flow, object-selection endpoints, meta storage and output escaping, and the [rwmb_meta] shortcode.

Plugin Security Certification (PSC-2026-65698): “Web Accessibility (formally known as Ally) – WCAG Scanning, Guided Fixes, Usability Widget” – Version 4.1.4

Plugin Security Certification (PSC-2026-65698): “Web Accessibility (formally known as Ally) – WCAG Scanning, Guided Fixes, Usability Widget” – Version 4.1.4

Accessibility widgets combine public front-end output with administrator-managed settings, on-page WCAG scanning, and guided fixes that change how content is presented to visitors. Web Accessibility (formally known as Ally) – WCAG Scanning, Guided Fixes, Usability Widget version 4.1.4 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65698. The review focused on REST API authorization, the public analytics endpoint, scan and remediation data handling, SVG icon uploads, and safe rendering of administrator-controlled widget settings.

Plugin Security Certification (PSC-2026-65697): “Child Theme Configurator” – Version 2.6.7

Plugin Security Certification (PSC-2026-65697): “Child Theme Configurator” – Version 2.6.7

Child theme utilities inspect installed themes and can create or modify PHP, CSS, and configuration files inside the WordPress themes directory. Child Theme Configurator version 2.6.7 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65697. The review focused on administrative authorization, filesystem boundaries, theme and file selection, stylesheet parsing, template copying, and safe handling of configuration input.

Plugin Security Certification (PSC-2026-65696): “WP Mail Logging” – Version 1.16.0

Plugin Security Certification (PSC-2026-65696): “WP Mail Logging” – Version 1.16.0

Email logging plugins retain message bodies, recipient details, headers, attachments, and delivery errors that may contain sensitive operational data. WP Mail Logging version 1.16.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65696. The review focused on log access, stored message rendering, attachment references, search and bulk actions, resend requests, and protection of plugin settings.

Plugin Security Certification (PSC-2026-65695): “CookieAdmin – Cookie Consent Banner” – Version 1.2.3

Plugin Security Certification (PSC-2026-65695): “CookieAdmin – Cookie Consent Banner” – Version 1.2.3

Cookie consent tools combine public banner output with administrator-managed rules that determine when scripts and cookie groups can load. CookieAdmin – Cookie Consent Banner version 1.2.3 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65695. The review focused on protected configuration, consent state processing, script identification rules, cookie scan data, and safe rendering of visitor choices.