Publish Confirm Message
Publish Confirm Message has one disclosed vulnerability in the WordSec catalog, all reported in 2023; it is fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for Publish Confirm Message has a vendor fix available, so running the current release closes it.
All of these findings were reported by Taihei Shimamine. Publish Confirm Message is installed on roughly 100 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
CVE-2023-32124Publish Confirm Message <= 1.3.1 - Cross-Site Request Forgery
Read the full analysisVulnerability Records

Publish Confirm Message
Author
Arul Prasad J
This is a lightweight WordPress plugin that adds an extra confirmation dialog when clicking the Publish button in the Classic Editor, helping to prevent accidental publishing. Never publish by accident again! This plugin adds confirmation dialogs for publishing actions in the Classic Editor. When working with page builders such as Elementor, WPBakery, confirmations are displayed when publishing or updating content via the WordPress editor controls rather than the builder’s own interface. If you love this plugin, buy me a cup of coffee
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C