Advanced Settings 3

Advanced Settings 3 has 3 disclosed vulnerabilities in the WordSec catalog, all reported in 2025; all 3 are fixed as of September 2026. Their average CVSS score is 5.8, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 1 high. 2025 was the busiest year with 3 disclosures.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 2 of the records (67%). Other recurring categories include Unrestricted Upload Of File With Dangerous Type.

Every one of the 3 issues recorded for Advanced Settings 3 has a vendor fix available, so running the current release closes all known holes.

2 independent researchers contributed these findings, most of them (2) reported by R1sky. Advanced Settings 3 is installed on roughly 200 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSMedium
5.8/ 10
Patch Coverage100%
Open

0

Fixed

3

Get automatic notifications for all Advanced Settings 3 vulnerabilities before they are exploited.

Highest severity on recordCVSS 8.8CVE-2025-58996

Advanced Settings <= 3.1.1 - Authenticated (Author+) Arbitrary File Upload

Read the full analysis

Vulnerability Records

3 records
Advanced Settings 3 banner
Latestv3.3.1

Advanced Settings 3

Helmut Wandl

Author

Helmut Wandl

3.9(7)
78/100
Last Updated
2026-07-18 (2mo ago)
Active Installs
200+
Downloads
34,255
Requires WP
5.0.0+
Requires PHP
7.4+
Tested up to
WP 7.0.4
Created
2012-07-09 (14y ago)

Advanced Settings is a powerful WordPress plugin that provides settings you would expect to find in the WordPress core. It is lightweight, performant and offers a modern, fast and user-friendly interface. 🚀 PERFORMANCE Advanced Settings 3 is optimized for extreme performance. It even loads only necessary PHP. → details in FAQ 🪶 LIGHTWEIGHT Advanced Settings 3 is lightweight (only about 0.5 MB) and discreet (no dashboard hijacking). → details in FAQ 🔒 SECURITY Advanced Settings 3 has been independently reviewed for security vulnerabilities via Patchstack. → details in FAQ ✳️ INFO ABOUT THE 2 BAD RATINGS Bad ratings occurred in 2017 because users used outdated PHP versions, but can’t happen again. → details in FAQ — FEATURES 🩷 FEATURE REQUESTS ARE WELCOME Advanced Settings 3 was developed to help as many users as possible. If you’d like to see a feature added to this plugin, please let us know. Don’t worry, we’ll keep the plugin fast and lean; this is a high priority for us. We’ll only implement features that don’t conflict with this. Admin Area Hide the top admin bar for all users in the frontend Hide WordPress update message in dashboard Hide the welcome panel in the dashboard Hide the default widgets in the dashboard 💥 new Customize the admin area branding 💥 new Frontend Remove PHP version from HTTP headers 💥 new Add security HTTP headers 💥 new Automatically add FavIcon (when favicon.ico, favicon.png or favicon.svg exists in template folder) Add Facebook Open Graph meta tags Remove shortlink meta tag Remove RSD (Weblog Client Link) meta tag Remove WordPress generator meta tag Automatically add description meta tag using blog description and post excerpt (SEO) Disable author pages Remove wptexturize filter Disable auto embed of external content 💥 new Limit excerpt length Add “Read more” link after excerpt Remove trackbacks and pingbacks from comment count Protect email addresses from spam bots Compress HTML code Remove HTML comments (except conditional IE comments) Disable emoji image replacement Editing Disable posts auto saving Limit post revisions 💥 new Allow SVG uploads for admins 💥 new Downsize images on upload to max size Set JPEG quality Add thumbnail support Automatically generate post thumbnail (from first image in post) System Hide default WordPress favicon Disable comment system Disable XML-RPC 💥 new Disable public REST API 💥 new Prevent installation of new default WordPress themes during core updates Disable email notifications for core updates Disable email notifications for plugin updates Disable email notifications for theme updates Create custom post types 💥 renewed Developer Display SQL queries and page load time Configuration Show/hide deprecated features Show/hide experimental features Configure tracking consent for feature usage statistics Configure visibility of user guide Contribute on github: github.com/eHtmlu/advanced-settings

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C