Trusty Whistleblowing Solution
Trusty Whistleblowing Solution has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 5.3 out of 10.
The most common weakness is Missing Authorization, behind 1 of the records (100%).
The one issue recorded for Trusty Whistleblowing Solution has a vendor fix available, so running the current release closes it.
All of these findings were reported by Hiro. Trusty Whistleblowing Solution is installed on roughly 400 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2025-52818Trusty Whistleblowing <= 2.0.1 - Missing Authorization
Read the full analysisVulnerability Records

Trusty Whistleblowing Solution
Author
Dejan Jasnic
Trusty is an instantly available, customizable and secure web-based whistleblowing solution developed by compliance experts. It is built to support internal reporting obligations under the EU Whistleblower Protection Directive and related national whistleblowing laws. The solution consists of customizable front-end webpages for whistleblowers and an intuitive case management tool for your team. The reporting channel is a dedicated web page where employees and stakeholders can submit reports anonymously or identified, depending on their choice and your configuration. Once a report is submitted, a secure inbox is created for confidential two-way communication between the reporter and your designated responders. The case management tool lets you receive, document and handle reports in one place. Depending on your plan, Trusty supports report handling, status tracking, notes, file attachments, retention settings, follow-up activities, secure reporter dialogue, notifications, workflows and reporting insights. Also available: Cybersecurity Vulnerability Reporting for organisations subject to the NIS2 Directive. Lite, Standard and Advanced plans are available depending on the number of users, reporting languages, notifications, workflows and governance features your organisation needs. The plugin is free to install and connects your WordPress site to Trusty, a paid whistleblowing service. Every plan starts with a free 7-day trial. Visit trusty.report/plans for current plans and pricing.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C