Supervisor
Supervisor has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Missing Authorization, behind 1 of the records (100%).
The one issue recorded for Supervisor has a vendor fix available, so running the current release closes it.
All of these findings were reported by Jonas Benjamin Friedli. Supervisor is installed on roughly 100 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
CVE-2025-11887Supervisor <= 1.3.2 - Missing Authorization to Authenticated (Subscriber+) Settings Update
Read the full analysisVulnerability Records
Supervisor
Author
Tiago Hillebrandt
Optimize and Secure Your WordPress Site with Supervisor Boost the performance and security of your WordPress site effortlessly with our powerful plugin. Supervisor provides vital insights into your site’s health directly through your WordPress Dashboard. Key Features: Performance Optimization: Improve your site’s speed by cleaning up transients and deactivating unnecessary autoload options. Brute Force Protection: Shield your site from attacks with robust security measures designed to prevent unauthorized access. Web Server Software Verification: Ensure your server software is up-to-date, keeping your site running smoothly and securely. SSL Certificate Monitoring: Stay informed about your SSL certificate status with dashboard notifications for impending expirations or expired certificates. Experience a faster and more secure WordPress site with Supervisor. Download it today and feel the difference!
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C