Plugin Security Certification (PSC-2026-65710): “Instant Indexing for Google” – Version 1.1.22

Plugin Security Certification (PSC-2026-65710): “Instant Indexing for Google” – Version 1.1.22

Search submission plugins handle site URLs and service credentials while sending manual or automatic requests to external indexing endpoints. Instant Indexing for Google version 1.1.22 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65710. The review focused on settings permissions, credential handling, URL validation, manual and bulk submissions, automatic post events, remote API requests, response output, post type exclusions, and IndexNow controls.

Plugin Security Certification (PSC-2026-65709): “Disable XML-RPC” – Version 1.0.1

Plugin Security Certification (PSC-2026-65709): “Disable XML-RPC” – Version 1.0.1

XML-RPC controls affect remote publishing clients and other integrations that communicate with WordPress through the XML-RPC endpoint. Disable XML-RPC version 1.0.1 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65709. The review focused on plugin bootstrap behavior, filter registration, XML-RPC availability, activation state, compatibility with the WordPress request path, and the absence of unnecessary user input surfaces.

Plugin Security Certification (PSC-2026-65708): “Simple CAPTCHA with Cloudflare Turnstile” – Version 1.43.2

Plugin Security Certification (PSC-2026-65708): “Simple CAPTCHA with Cloudflare Turnstile” – Version 1.43.2

Anti-spam integrations accept challenge tokens on public forms and exchange them with an external verification service before a submission is allowed. Simple CAPTCHA with Cloudflare Turnstile version 1.43.2 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65708. The review focused on settings permissions, key handling, challenge token validation, server side verification, form integration, whitelisting, failsafe behavior, and diagnostic logging.

Plugin Security Certification (PSC-2026-65707): “Widget Importer & Exporter” – Version 1.6.1

Plugin Security Certification (PSC-2026-65707): “Widget Importer & Exporter” – Version 1.6.1

Widget migration tools process configuration data that can create or update active and inactive widget instances across a WordPress site. Widget Importer & Exporter version 1.6.1 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65707. The review focused on upload handling, JSON data validation, administrator permissions, widget instance import, export output, duplicate detection, unsupported widgets, and developer hooks.

CVE-2026-10096 – Qi Blocks – Author+ IDOR – POC

CVE-2026-10096 – Qi Blocks – Author+ IDOR – POC

CVE-2026-10096 affects Qi Blocks through version 1.4.9 and allows authenticated Author+ users to overwrite stored styles for posts they cannot edit through the qi-blocks/v1/update-styles REST route. The endpoint trusts the supplied page_id after checking only edit_posts and publish_posts, so a user can target another author’s post. Reserved template and widget values broaden the impact to shared site surfaces, enabling persistent frontend defacement, hidden content, and degraded page usability. The issue is fixed in version 1.5.0.

Plugin Security Certification (PSC-2026-65702): “WP Crontrol” – Version 1.21.2

Plugin Security Certification (PSC-2026-65702): “WP Crontrol” – Version 1.21.2

Cron management plugins can inspect, create, pause, delete, and immediately execute scheduled tasks that affect many parts of a WordPress site. WP Crontrol version 1.21.2 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65702. The review focused on authorization for event management, request integrity, callback and argument display, custom schedules, URL validation, bulk actions, and exported event data.

Plugin Security Certification (PSC-2026-65701): “AMP” – Version 2.5.5

Plugin Security Certification (PSC-2026-65701): “AMP” – Version 2.5.5

AMP integrations transform WordPress output, validate generated markup, and may direct visitors between standard and optimized page variants. AMP version 2.5.5 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65701. The review focused on administrative settings, markup sanitization, validation data, template processing, component handling, and safe page delivery.

Plugin Security Certification (PSC-2026-65700): “Converter for Media – Optimize images | Convert WebP & AVIF” – Version 6.6.5

Plugin Security Certification (PSC-2026-65700): “Converter for Media – Optimize images | Convert WebP & AVIF” – Version 6.6.5

Image optimization plugins read files from the uploads directory, create alternative formats, and route visitor requests to generated assets. Converter for Media – Optimize images | Convert WebP & AVIF version 6.6.5 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65700. The review focused on source file validation, path confinement, conversion jobs, generated output, delivery rules, and permission checks around administrative actions.

Plugin Security Certification (PSC-2026-65697): “Child Theme Configurator” – Version 2.6.7

Plugin Security Certification (PSC-2026-65697): “Child Theme Configurator” – Version 2.6.7

Child theme utilities inspect installed themes and can create or modify PHP, CSS, and configuration files inside the WordPress themes directory. Child Theme Configurator version 2.6.7 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65697. The review focused on administrative authorization, filesystem boundaries, theme and file selection, stylesheet parsing, template copying, and safe handling of configuration input.

Plugin Security Certification (PSC-2026-65696): “WP Mail Logging” – Version 1.16.0

Plugin Security Certification (PSC-2026-65696): “WP Mail Logging” – Version 1.16.0

Email logging plugins retain message bodies, recipient details, headers, attachments, and delivery errors that may contain sensitive operational data. WP Mail Logging version 1.16.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65696. The review focused on log access, stored message rendering, attachment references, search and bulk actions, resend requests, and protection of plugin settings.