1-Click Disable All
1-Click Disable All has one disclosed vulnerability in the WordSec catalog, all reported in 2023; it is fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for 1-Click Disable All has a vendor fix available, so running the current release closes it.
All of these findings were reported by Veerla Saikumar. The current release is tested up to WordPress 7.1.
CVE-2024-217491 click disable all <= 1.0.1 - Cross-Site Request Forgery
Read the full analysisVulnerability Records
1-Click Disable All
Author
Atakan Au
This lightweight tool adds a “Deactivate all” link to the Plugins page and a confirmation screen under Tools → Disable All Plugins. Perfect for: – Plugin conflict debugging – Maintenance / emergency access recovery – When a bad plugin locks you out of wp-admin Important Warning: Deactivation is immediate. There is no “Reactivate All” button, so you must turn your plugins back on individually. Keep FTP access handy in case reactivating a plugin causes a fatal error. Visit my blog for details, support and feedback: 1-Click Disable All Plugin
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C