Plugin Security Certification (PSC-2026-64691): “Complianz – Terms and Conditions” – Version 1.4.0

Plugin Security Certification (PSC-2026-64691): “Complianz – Terms and Conditions” – Version 1.4.0

Legal document generators collect business and website details, store wizard answers, publish generated pages, and may process consumer withdrawal submissions. Complianz – Terms and Conditions version 1.4.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64691, confirming that the review focused on wizard permissions, stored configuration, document output, withdrawal form requests, email handling, anti-abuse controls, and safe rendering of generated text.

Plugin Security Certification (PSC-2026-64690): “Limit Login Attempts” – Version 1.7.2

Plugin Security Certification (PSC-2026-64690): “Limit Login Attempts” – Version 1.7.2

Login protection plugins operate directly on authentication requests, retry counters, lockouts, cookies, client addresses, and administrative notifications. Limit Login Attempts version 1.7.2 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64690, confirming that the review focused on retry tracking, IP handling, lockout enforcement, authentication cookie checks, configuration access, and safe logging of failed attempts.

Plugin Security Certification (PSC-2026-64689): “WebP Express” – Version 0.25.15

Plugin Security Certification (PSC-2026-64689): “WebP Express” – Version 0.25.15

Image conversion plugins process uploaded files, write derivatives, update rewrite rules, and may invoke local or remote converters. WebP Express version 0.25.15 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64689, confirming that the review focused on file access, conversion inputs, generated output paths, rewrite behavior, converter configuration, and protection of privileged settings.

Plugin Security Certification (PSC-2026-64688): “Admin Menu Editor” – Version 1.15.2

Plugin Security Certification (PSC-2026-64688): “Admin Menu Editor” – Version 1.15.2

Dashboard customization tools influence navigation, capability checks, menu visibility, redirects, and access to administrative screens. Admin Menu Editor version 1.15.2 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64688, confirming that the review focused on settings authorization, capability handling, menu configuration integrity, redirect behavior, and safe processing of custom labels, URLs, and icons.

Plugin Security Certification (PSC-2026-64687): “Breeze Cache” – Version 2.5.13

Plugin Security Certification (PSC-2026-64687): “Breeze Cache” – Version 2.5.13

Caching and optimization plugins rewrite responses, manage cache files, and interact with CDNs and remote asset sources. Breeze Cache version 2.5.13 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64687, confirming that the review focused on cache storage, purge operations, optimization settings, remote downloads, administrator controls, and safe handling of generated assets.

Plugin Security Certification (PSC-2026-64686): “Disable Comments – Remove Comments & Stop Spam [Multi-Site Support]” – Version 2.8.0

Plugin Security Certification (PSC-2026-64686): “Disable Comments – Remove Comments & Stop Spam [Multi-Site Support]” – Version 2.8.0

Comment management tools affect public submission paths, administration screens, feeds, APIs, and multisite policy. Disable Comments – Remove Comments & Stop Spam [Multi-Site Support] version 2.8.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64686, confirming that the review focused on settings access, request validation, comment-related endpoints, role-aware controls, and consistent enforcement across supported site contexts.

Plugin Security Certification (PSC-2026-64685): “Site Kit by Google – Analytics, Search Console, AdSense, Speed” – Version 1.186.0

Plugin Security Certification (PSC-2026-64685): “Site Kit by Google – Analytics, Search Console, AdSense, Speed” – Version 1.186.0

Analytics and advertising integrations connect a WordPress dashboard to external services and expose site performance data to privileged users. Site Kit by Google – Analytics, Search Console, AdSense, Speed version 1.186.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64685, confirming that the review focused on service connections, dashboard data access, REST requests, administrator actions, and safe rendering of remote metrics.

CVE-2026-9125 – Presto Player – Contributor+ Stored XSS – POC

CVE-2026-9125 – Presto Player – Contributor+ Stored XSS – POC

CVE-2026-9125 affects Presto Player and is an authenticated Contributor+ Stored Cross-Site Scripting vulnerability in versions up to and including 4.2.0. A malicious presto_player_overlay shortcode can preserve a javascript: URI in link_url, allowing attacker-controlled JavaScript to run in the WordPress origin when another user clicks the overlay during playback.