The Tribal Plugin
The Tribal Plugin has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2025 and 2026; all 3 are fixed as of September 2026. Their average CVSS score is 5.0, and the most serious one scores 5.3 out of 10. 2025 was the busiest year with 2 disclosures.
The most common weakness is Exposure Of Sensitive Information To An Unauthorized Actor, behind 2 of the records (67%). Other recurring categories include Cross-Site Scripting.
Every one of the 3 issues recorded for The Tribal Plugin has a vendor fix available, so running the current release closes all known holes.
All of these findings were reported by Nabil Irawan. The Tribal Plugin is installed on roughly 700 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2026-39709The Tribal <= 1.3.4 - Unauthenticated Information Exposure
Read the full analysisVulnerability Records

The Tribal Plugin
Author
thetechtribe
The Tech Tribe plugin allows members of the Tech Tribe to automatically post blog content to their website from the Monthly Marketing Packs included in their Membership. It allows members to: Set what Author they want as Default on all the Posts Decide between Automatic posting or Manual posting in case they want to check first You can find out more about The Tech Tribe at: https://thetechtribe.com/
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C