Unconfirmed
Unconfirmed has one disclosed vulnerability in the WordSec catalog, all reported in 2014; it is fixed as of September 2026. Their average CVSS score is 7.1, and the most serious one scores 7.1 out of 10. Severity breakdown: 0 critical and 1 high.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Unconfirmed has a vendor fix available, so running the current release closes it.
All of these findings were reported by Mallory Adams. Unconfirmed is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.4.10.
CVE-2014-100018Unconfirmed < 1.2.5 - Reflected Cross-Site Scripting
Read the full analysisVulnerability Records
Unconfirmed
Author
Boone Gorges
If you run a WordPress or BuddyPress installation, you probably know that some of the biggest administrative headaches come from the activation process. Activation emails may be caught by spam filters, deleted unwillingly, or simply not understood. Yet WordPress itself has no UI for viewing and managing unactivated members. Unconfirmed creates a Dashboard panel under the Users menu (Network Admin > Users on Multisite) that shows a list of unactivated user registrations. For each registration, you have the option of resending the original activation email, or manually activating the user. Note that the plugin works for the following configurations: 1. Multisite, with or without BuddyPress 2. Single site, with BuddyPress used for user registration There is currently no support for single-site WP registration without BuddyPress.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C