How the WordPress mu-plugins backdoor works: a hidden loader in wp-content/mu-plugins that auto-runs, stashes its payload in the database, and creates a rogue admin — plus indicators of compromise, detection and removal.
WordPress File Integrity Monitoring: Detect File Changes with Security by CleanTalk
Plugin Security Certification (PSC-2026-65705): ‘Presto Player’ – Version 4.5.1

Media player plugins embed and stream video and audio, render player markup on the front end, store per-media settings, and expose REST and AJAX endpoints for playback data and analytics. Presto Player version 4.5.1 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65705, confirming that the review focused on media block rendering and output escaping, REST and AJAX endpoint authorization, settings storage, and handling of external video sources and uploaded media.
Plugin Security Certification (PSC-2026-65706): ‘YITH WooCommerce Compare’ – Version 3.14.0

Product comparison plugins add and remove items through AJAX, store the visitor’s comparison list, and render a table of product attributes on the front end. YITH WooCommerce Compare version 3.14.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65706, confirming that the review focused on the AJAX add/remove endpoints, product ID handling, output escaping in the comparison table, and sanitization of the plugin’s settings.
Plugin Security Certification (PSC-2026-65704): ‘Easy HTTPS Redirection (SSL)’ – Version 2.0.1

HTTPS redirection plugins intercept incoming requests, decide the target scheme, and issue redirects while reading proxy and forwarded headers. Easy HTTPS Redirection (SSL) version 2.0.1 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65704, confirming that the review focused on redirect target handling, settings storage, capability and nonce checks, and safe processing of proxy and forwarded headers.
Plugin Security Certification (PSC-2026-65703): ‘WP 2FA – Two-factor authentication for WordPress’ – Version 4.1.0

Two-factor authentication plugins handle login flows, generate and store shared secrets, issue one-time and backup codes, and enforce access policies across user roles. WP 2FA version 4.1.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65703, confirming that the review focused on the 2FA setup wizard, TOTP secret handling, one-time and backup code validation, capability and nonce checks on settings, and role-based enforcement.
Plugin Security Certification (PSC-2026-65699): “Meta Box – A Framework for Dynamic Websites” – Version 5.15.1

Custom fields frameworks render administrator-defined fields on post, term, user, and settings screens, store arbitrary meta, and expose AJAX endpoints for selecting posts, users, and terms, uploading and deleting files, and fetching oEmbeds. Meta Box – A Framework for Dynamic Websites version 5.15.1 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65699. The review focused on AJAX authorization and nonces, the file upload and delete flow, object-selection endpoints, meta storage and output escaping, and the [rwmb_meta] shortcode.
Plugin Security Certification (PSC-2026-65698): “Web Accessibility (formally known as Ally) – WCAG Scanning, Guided Fixes, Usability Widget” – Version 4.1.4

Accessibility widgets combine public front-end output with administrator-managed settings, on-page WCAG scanning, and guided fixes that change how content is presented to visitors. Web Accessibility (formally known as Ally) – WCAG Scanning, Guided Fixes, Usability Widget version 4.1.4 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65698. The review focused on REST API authorization, the public analytics endpoint, scan and remediation data handling, SVG icon uploads, and safe rendering of administrator-controlled widget settings.
Plugin Security Certification (PSC-2026-64695): “Drag and Drop Multiple File Upload for Contact Form 7” – Version 1.4.0

File upload add-ons for Contact Form 7 receive untrusted files from anonymous website visitors, write them into the WordPress uploads directory, and expose AJAX endpoints for uploading and deleting those files. Drag and Drop Multiple File Upload for Contact Form 7 version 1.4.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64695, confirming that the review focused on unauthenticated AJAX upload handling, file-extension and MIME validation, filename sanitization and anti-script renaming, upload-path confinement, token-based file-deletion authorization, request rate limiting, and output escaping in the settings screen.


