SMu Manual DoFollow
SMu Manual DoFollow has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for SMu Manual DoFollow has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by Nguyen Xuan Chien. SMu Manual DoFollow is installed on roughly 100 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 4.1.42.
CVE-2025-49031SMu Manual DoFollow <= 1.8.1 - Reflected Cross-Site Scripting
Read the full analysisVulnerability Records
SMu Manual DoFollow
Author
Stefan M.
This plugin will set all Trackbacks and Pingbacks automatically to DoFollow Links. The user comments will get after X comments from a unique mailaddress automatically DoFollow status. All other comments have NoFollow, except the Admin enable manually the DoFollow Status. The status which is set manual (if DoFollow or NoFollow) will overrides the automatical process. So, you have the control if someone gets sooner the DoFollow status, or never maybe. Of corse, the automatism can be disabled to do the hole work manually. You get an support automatism, that you don’t need to check daily, but have the full control power. Additonal this plugin validated all DoFollow URLs and will notice if there are broken links. Broken Links are very bad the Rank in the Search Engines (SEO). Home Page of the Plugin: IT Blögg – WordPress Manual DoFollow Plugin If you have a wish for new functions, please contact me.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C