cleantalk
Vulnerabilities and Security Researches

Instant Images – One Click Image Uploads from Unsplash, Openverse, Pixabay and Pexels, PSC-2026-64662

PSC, Research URL

PSC-2026-64662

Published on
May 26, 2026
Research Description
Image import plugins bridge WordPress with external media providers, proxy services, remote image URLs, metadata processing, and the local Media Library. That workflow improves publishing speed, but it also expands the attack surface around remote downloads, MIME validation, alt text and caption handling, attribution metadata, and editor integrations. Instant Images version 7.1.1 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64662, confirming that the plugin was reviewed from a secure code perspective with attention to common exploitation paths for remote image import and media-library workflow plugins.
Affected versions
Min 7.1.1, max 7.1.1.
Status
SAFE & CERTIFIED