User Domain Whitelist
User Domain Whitelist has one disclosed vulnerability in the WordSec catalog, all reported in 2014; it is fixed as of September 2026. Their average CVSS score is 8.8, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 1 high.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for User Domain Whitelist has a vendor fix available, so running the current release closes it.
User Domain Whitelist is installed on roughly 300 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 0.
CVE-2014-10381User Domain Whitelist <= 1.4 - Cross-Site Request Forgery
Read the full analysisVulnerability Records
User Domain Whitelist
Author
Warren Harrison
The User Domain Whitelist/Blacklist plugin limits user registration to only registrants with an email address from the domain white list below OR prevents registrants with an email address from the domain black list below from registering. For example, hortense@example.com would only be allowed to register if example.com appeared in the domain white list. Conversely, hortense@example.com would not be allowed to register if example.com appeared in the domain black list. Anyone attempting to register using an email address outside the white list or inside te black list will receive the error message below.Anyone attempting to register using an email address outside the white list will receive an error message. Both the domain whitelist and the error message can be modified via the plugin options page (available under the Settings menu).
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C