Publish Confirm Message

Publish Confirm Message has one disclosed vulnerability in the WordSec catalog, all reported in 2023; it is fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).

The one issue recorded for Publish Confirm Message has a vendor fix available, so running the current release closes it.

All of these findings were reported by Taihei Shimamine. Publish Confirm Message is installed on roughly 100 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.

Strategic Overview

Avg CVSSMedium
4.3/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Publish Confirm Message vulnerabilities before they are exploited.

Highest severity on recordCVSS 4.3CVE-2023-32124

Publish Confirm Message <= 1.3.1 - Cross-Site Request Forgery

Read the full analysis

Vulnerability Records

1 records
Publish Confirm Message banner
Latestv2.1

Publish Confirm Message

Arul Prasad J

Author

Arul Prasad J

5.0(1)
100/100
Last Updated
2026-01-06 (8mo ago)
Active Installs
100+
Downloads
9,043
Requires WP
4.2+
Requires PHP
0+
Tested up to
WP 6.8.8
Created
2020-03-11 (7y ago)

This is a lightweight WordPress plugin that adds an extra confirmation dialog when clicking the Publish button in the Classic Editor, helping to prevent accidental publishing. Never publish by accident again! This plugin adds confirmation dialogs for publishing actions in the Classic Editor. When working with page builders such as Elementor, WPBakery, confirmations are displayed when publishing or updating content via the WordPress editor controls rather than the builder’s own interface. If you love this plugin, buy me a cup of coffee

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C