CVE-2026-5821 – Image Optimizer – Author+ File Deletion – POC

CVE-2026-5821 – Image Optimizer – Author+ File Deletion – POC

CVE-2026-5821 affects Image Optimizer through version 1.7.4 and allows an authenticated Author to cause arbitrary file deletion through attachment backup metadata. The plugin trusts stored backup paths during attachment cleanup without checking that they belong to the expected image backups. Files writable by the web server may be removed, causing data loss, denial of service, or weakened site protection. The issue is fixed in version 1.7.5.

CVE-2026-11592 – Icegram Express – Missing Authorization – POC

CVE-2026-11592 – Icegram Express – Missing Authorization – POC

CVE-2026-11592 affects Email Subscribers & Newsletters, also known as Icegram Express, through version 5.9.27. A Contributor can open the hidden es_template editor, read the shared ig-es-admin-ajax-nonce from ig_es_js_data.security, and reuse it against AJAX handlers that do not enforce an effective capability check. The exposed workflow permits unauthorized mail setting changes, audience and campaign manipulation, contact imports, persistent workflows, and immediate email dispatch. The issue is fixed in version 5.9.28.

Plugin Security Certification (PSC-2026-65710): “Instant Indexing for Google” – Version 1.1.22

Plugin Security Certification (PSC-2026-65710): “Instant Indexing for Google” – Version 1.1.22

Search submission plugins handle site URLs and service credentials while sending manual or automatic requests to external indexing endpoints. Instant Indexing for Google version 1.1.22 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65710. The review focused on settings permissions, credential handling, URL validation, manual and bulk submissions, automatic post events, remote API requests, response output, post type exclusions, and IndexNow controls.

Plugin Security Certification (PSC-2026-65709): “Disable XML-RPC” – Version 1.0.1

Plugin Security Certification (PSC-2026-65709): “Disable XML-RPC” – Version 1.0.1

XML-RPC controls affect remote publishing clients and other integrations that communicate with WordPress through the XML-RPC endpoint. Disable XML-RPC version 1.0.1 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65709. The review focused on plugin bootstrap behavior, filter registration, XML-RPC availability, activation state, compatibility with the WordPress request path, and the absence of unnecessary user input surfaces.

Plugin Security Certification (PSC-2026-65708): “Simple CAPTCHA with Cloudflare Turnstile” – Version 1.43.2

Plugin Security Certification (PSC-2026-65708): “Simple CAPTCHA with Cloudflare Turnstile” – Version 1.43.2

Anti-spam integrations accept challenge tokens on public forms and exchange them with an external verification service before a submission is allowed. Simple CAPTCHA with Cloudflare Turnstile version 1.43.2 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65708. The review focused on settings permissions, key handling, challenge token validation, server side verification, form integration, whitelisting, failsafe behavior, and diagnostic logging.

Plugin Security Certification (PSC-2026-65707): “Widget Importer & Exporter” – Version 1.6.1

Plugin Security Certification (PSC-2026-65707): “Widget Importer & Exporter” – Version 1.6.1

Widget migration tools process configuration data that can create or update active and inactive widget instances across a WordPress site. Widget Importer & Exporter version 1.6.1 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65707. The review focused on upload handling, JSON data validation, administrator permissions, widget instance import, export output, duplicate detection, unsupported widgets, and developer hooks.

Plugin Security Certification (PSC-2026-65705): ‘Presto Player’ – Version 4.5.1

Plugin Security Certification (PSC-2026-65705): ‘Presto Player’ – Version 4.5.1

Media player plugins embed and stream video and audio, render player markup on the front end, store per-media settings, and expose REST and AJAX endpoints for playback data and analytics. Presto Player version 4.5.1 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65705, confirming that the review focused on media block rendering and output escaping, REST and AJAX endpoint authorization, settings storage, and handling of external video sources and uploaded media.