Site Info
Site Info has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 2.7, and the most serious one scores 2.7 out of 10.
The most common weakness is Exposure Of Sensitive Information To An Unauthorized Actor, behind 1 of the records (100%).
The one issue recorded for Site Info has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by Bao - BlueRock. Site Info is installed on roughly 60 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 4.9.31.
CVE-2025-58866Site Info <= 1.1 - Authenticated (Editor+) Information Exposure
Read the full analysisVulnerability Records

Site Info
Author
Rami Yushuvaev
This simple, but useful, plugin adds a widget to your WordPress dashboard, displaying a list of site information. Showing the site name, tagline, site URL, admin URL, admin language, text direction, WordPress version and PHP version. It’s very handy if you want to see your site general information in one place – your sites dashboard. More info To read how this plugin was developed, including code examples and screenshots, visit: https://GenerateWP.com/introducing-dashboard-widgets-generator/ You can find the plugin source code in here: https://GenerateWP.com/snippet/nvl3vxg/ https://GenerateWP.com/snippet/2VvAap6/ And you can ask for more features using the original post comments area.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C