User Domain Whitelist

User Domain Whitelist has one disclosed vulnerability in the WordSec catalog, all reported in 2014; it is fixed as of September 2026. Their average CVSS score is 8.8, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 1 high.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).

The one issue recorded for User Domain Whitelist has a vendor fix available, so running the current release closes it.

User Domain Whitelist is installed on roughly 300 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 0.

Strategic Overview

Avg CVSSHigh
8.8/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all User Domain Whitelist vulnerabilities before they are exploited.

Highest severity on recordCVSS 8.8CVE-2014-10381

User Domain Whitelist <= 1.4 - Cross-Site Request Forgery

Read the full analysis

Vulnerability Records

1 records
Showing 1–1 of 1 reports
Plugin Profile
Latestvv1.5.1

User Domain Whitelist

Warren Harrison

Author

Warren Harrison

4.1(9)
82/100
Last Updated
2017-12-25 (9y ago)
Active Installs
300+
Downloads
14,382
Requires WP
2.8.2+
Requires PHP
0+
Tested up to
WP 0
Created
2009-08-22 (17y ago)

The User Domain Whitelist/Blacklist plugin limits user registration to only registrants with an email address from the domain white list below OR prevents registrants with an email address from the domain black list below from registering. For example, hortense@example.com would only be allowed to register if example.com appeared in the domain white list. Conversely, hortense@example.com would not be allowed to register if example.com appeared in the domain black list. Anyone attempting to register using an email address outside the white list or inside te black list will receive the error message below.Anyone attempting to register using an email address outside the white list will receive an error message. Both the domain whitelist and the error message can be modified via the plugin options page (available under the Settings menu).

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C