The Tribal Plugin

The Tribal Plugin has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2025 and 2026; all 3 are fixed as of September 2026. Their average CVSS score is 5.0, and the most serious one scores 5.3 out of 10. 2025 was the busiest year with 2 disclosures.

The most common weakness is Exposure Of Sensitive Information To An Unauthorized Actor, behind 2 of the records (67%). Other recurring categories include Cross-Site Scripting.

Every one of the 3 issues recorded for The Tribal Plugin has a vendor fix available, so running the current release closes all known holes.

All of these findings were reported by Nabil Irawan. The Tribal Plugin is installed on roughly 700 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.

Strategic Overview

Avg CVSSMedium
5.0/ 10
Patch Coverage100%
Open

0

Fixed

3

Get automatic notifications for all The Tribal Plugin vulnerabilities before they are exploited.

Highest severity on recordCVSS 5.3CVE-2026-39709

The Tribal <= 1.3.4 - Unauthenticated Information Exposure

Read the full analysis

Vulnerability Records

3 records
The Tribal Plugin banner
Latestv1.3.5

The Tribal Plugin

thetechtribe

Author

thetechtribe

5.0(1)
100/100
Last Updated
2026-04-13 (5mo ago)
Active Installs
700+
Downloads
16,054
Requires WP
5.0+
Requires PHP
7.0+
Tested up to
WP 6.9.7
Created
2021-11-11 (5y ago)

The Tech Tribe plugin allows members of the Tech Tribe to automatically post blog content to their website from the Monthly Marketing Packs included in their Membership. It allows members to: Set what Author they want as Default on all the Posts Decide between Automatic posting or Manual posting in case they want to check first You can find out more about The Tech Tribe at: https://thetechtribe.com/

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C