Automatic Domain Changer
Automatic Domain Changer has one disclosed vulnerability in the WordSec catalog, all reported in 2022; it is fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Automatic Domain Changer has a vendor fix available, so running the current release closes it.
All of these findings were reported by WPScanTeam. Automatic Domain Changer is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
Automatic Domain Changer <= 2.0.2 - Reflected Cross-Site Scripting
Read the full analysisVulnerability Records

Automatic Domain Changer
Author
nuagelab
This plugin automatically detects a domain name change, and updates all the WordPress tables in the database to reflect this change. Features Easily migrate a WordPress site from one domain to another Migrate www.domain.com and domain.com at once Migrate http and https links at once Feedback We are open for your suggestions and feedback – Thank you for using or trying out one of our plugins! Drop us a line @nuagelab on Twitter Follow us on our Facebook page Drop us a line at wordpress-plugins@nuagelab.com Translations English French Spanish Slovak
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C