Trusty Whistleblowing Solution

Trusty Whistleblowing Solution has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 5.3 out of 10.

The most common weakness is Missing Authorization, behind 1 of the records (100%).

The one issue recorded for Trusty Whistleblowing Solution has a vendor fix available, so running the current release closes it.

All of these findings were reported by Hiro. Trusty Whistleblowing Solution is installed on roughly 400 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSMedium
5.3/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Trusty Whistleblowing Solution vulnerabilities before they are exploited.

Highest severity on recordCVSS 5.3CVE-2025-52818

Trusty Whistleblowing <= 2.0.1 - Missing Authorization

Read the full analysis

Vulnerability Records

1 records
Showing 1–1 of 1 reports
Trusty Whistleblowing Solution banner
Latestv2.0.3

Trusty Whistleblowing Solution

Dejan Jasnic

Author

Dejan Jasnic

5.0(15)
100/100
Last Updated
2026-07-02 (2mo ago)
Active Installs
400+
Downloads
9,032
Requires WP
5.6+
Requires PHP
7.4+
Tested up to
WP 7.0.4
Created
2022-04-01 (5y ago)

Trusty is an instantly available, customizable and secure web-based whistleblowing solution developed by compliance experts. It is built to support internal reporting obligations under the EU Whistleblower Protection Directive and related national whistleblowing laws. The solution consists of customizable front-end webpages for whistleblowers and an intuitive case management tool for your team. The reporting channel is a dedicated web page where employees and stakeholders can submit reports anonymously or identified, depending on their choice and your configuration. Once a report is submitted, a secure inbox is created for confidential two-way communication between the reporter and your designated responders. The case management tool lets you receive, document and handle reports in one place. Depending on your plan, Trusty supports report handling, status tracking, notes, file attachments, retention settings, follow-up activities, secure reporter dialogue, notifications, workflows and reporting insights. Also available: Cybersecurity Vulnerability Reporting for organisations subject to the NIS2 Directive. Lite, Standard and Advanced plans are available depending on the number of users, reporting languages, notifications, workflows and governance features your organisation needs. The plugin is free to install and connects your WordPress site to Trusty, a paid whistleblowing service. Every plan starts with a free 7-day trial. Visit trusty.report/plans for current plans and pricing.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C