Ultimate Category Excluder

Ultimate Category Excluder has one disclosed vulnerability in the WordSec catalog, all reported in 2020; it is fixed as of September 2026. Their average CVSS score is 8.8, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 1 high.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).

The one issue recorded for Ultimate Category Excluder has a vendor fix available, so running the current release closes it.

All of these findings were reported by Yaniv Nizry. Ultimate Category Excluder is installed on roughly 50,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSHigh
8.8/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Ultimate Category Excluder vulnerabilities before they are exploited.

Highest severity on recordCVSS 8.8CVE-2020-35135

Ultimate Category Excluder <= 1.1 - Cross-Site Request Forgery

Read the full analysis

Vulnerability Records

1 records
Ultimate Category Excluder banner
Latestv1.7

Ultimate Category Excluder

Marios Alexandrou

Author

Marios Alexandrou

4.3(78)
86/100
Last Updated
2026-08-20 (24d ago)
Active Installs
50,000+
Downloads
562,396
Requires WP
5.0+
Requires PHP
0+
Tested up to
WP 7.1
Created
2011-02-25 (16y ago)

Ultimate Category Excluder, abbreviated as UCE, is a WordPress plugin that allows you to quickly and easily exclude categories from your front page, archives, feeds, and searches. Just select which categories you want to be excluded, and UCE does all the work for you!

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C