Mediavine Control Panel

Mediavine Control Panel has 4 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2026; all 4 are fixed as of September 2026. Their average CVSS score is 5.1, and the most serious one scores 6.4 out of 10.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (25%). Other recurring categories include Cross-Site Scripting, Exposure Of Sensitive Information To An Unauthorized Actor.

Every one of the 4 issues recorded for Mediavine Control Panel has a vendor fix available, so running the current release closes all known holes.

4 independent researchers contributed these findings, one record each. Mediavine Control Panel is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSMedium
5.1/ 10
Patch Coverage100%
Open

0

Fixed

4

Get automatic notifications for all Mediavine Control Panel vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.4CVE-2024-43218

Mediavine Control Panel <= 2.10.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

4 records
Plugin Profile
Latestv2.10.12

Mediavine Control Panel

mediavine

Author

mediavine

4.2(5)
84/100
Last Updated
2026-08-25 (18d ago)
Active Installs
10,000+
Downloads
312,340
Requires WP
5.2+
Requires PHP
7.3+
Tested up to
WP 7.1
Created
2016-12-19 (10y ago)

Mediavine Control Panel connects your WordPress blog to your Mediavine account. Simply install the plugin, provide your mediavine account name, and take advantage of our cutting edge features Easy to use interface makes it simple to adjust your settings Keep your ads.txt up to date via redirecting to Mediavine’s servers or writing to a publisher’s filesystem Provide content creation tools for placing content like videos and playlists from your Dashboard into pages, posts, and categories Integrating with third party WordPress plugins (like WP Rocket) that may be preventing valid ad placement or ad loading Assist with the MCM approval process via Launch Mode Automatically generate your video sitemap Inserting ads on your Web Stories content Reporting Security Bugs Please report security bugs found in the Mediavine Control Panel plugin’s source code through the Patchstack Vulnerability Disclosure Program. The Patchstack team will assist you with verification, CVE assignment, and notify the developers of this plugin.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C