Pinterest Verify Meta Tag
Pinterest Verify Meta Tag has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 4.4, and the most serious one scores 4.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Pinterest Verify Meta Tag has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by Nabil Irawan. Pinterest Verify Meta Tag is installed on roughly 600 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 3.9.40.
CVE-2025-30941Pinterest Verify Meta Tag <= 1.3 - Authenticated (Administrator+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Pinterest Verify Meta Tag
Author
Marvie Pons
Pinterest Verify Meta Tag is a simple plugin which simply insert Pinterest meta tag verification code to the HEAD section of your site. Once you completed the verification process, people will see a checkmark next to your domain in your Pinterest profile and in pinner search results. That check mark emphasis you have confirmed the ownership of your blog or website on Pinterest. License This program is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version. This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details. You should have received a copy of the GNU General Public License along with Pinterest Verify Meta Tag. If not, see http://www.gnu.org/licenses/.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C