Connector to CiviCRM with CiviMcRestFace

Connector to CiviCRM with CiviMcRestFace has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2025; all 2 are fixed as of September 2026. Their average CVSS score is 5.7, and the most serious one scores 6.1 out of 10. 2025 was the busiest year with 2 disclosures.

The most common weakness is Cross-Site Scripting, behind 1 of the records (50%). Other recurring categories include Missing Authorization.

Every one of the 2 issues recorded for Connector to CiviCRM with CiviMcRestFace has a vendor fix available, so running the current release closes all known holes.

2 independent researchers contributed these findings, one record each. Connector to CiviCRM with CiviMcRestFace is installed on roughly 100 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.4.10.

Strategic Overview

Avg CVSSMedium
5.7/ 10
Patch Coverage100%
Open

0

Fixed

2

Get automatic notifications for all Connector to CiviCRM with CiviMcRestFace vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.1CVE-2025-32551

Connector to CiviCRM with CiviMcRestFace <= 1.0.8 - Reflected Cross-Site Scripting

Read the full analysis

Vulnerability Records

2 records
Plugin Profile
Latestv1.0.12

Connector to CiviCRM with CiviMcRestFace

Jaap Jansma

Author

Jaap Jansma

0.0(0)
0/100
Last Updated
2025-06-17 (1y ago)
Active Installs
100+
Downloads
6,019
Requires WP
5.2+
Requires PHP
7.2+
Tested up to
WP 6.4.10
Created
2020-12-31 (6y ago)

This plugin provides a connector to connect to a local or remote CiviCRM. This connector can then be reused by other plugins such as the Integration of CiviCRM’s Form Processor with Caldera Forms Configuration Configuration can be done under Settings > CiviCRM McRestFace Connections. Plugins using the CiviCRM McRestFace Connector Integration of CiviCRM’s Form Processor with Caldera Forms Funded by Artfulrobot CiviCooP Civiservice.de GmbH Bundesverband Soziokultur e.V. Article 19

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C