VigilanTor

VigilanTor has one disclosed vulnerability in the WordSec catalog, all reported in 2023; it is fixed as of September 2026. Their average CVSS score is 4.4, and the most serious one scores 4.4 out of 10.

The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).

The one issue recorded for VigilanTor has a vendor fix available, so running the current release closes it.

All of these findings were reported by Rio Darmawan. VigilanTor is installed on roughly 400 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.3.10.

Strategic Overview

Avg CVSSMedium
4.4/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all VigilanTor vulnerabilities before they are exploited.

Highest severity on recordCVSS 4.4CVE-2023-28695

VigilanTor <= 1.3.10 - Authenticated (Administrator+) Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

1 records
Plugin Profile
Latestv1.3.12

VigilanTor

drew010

Author

drew010

5.0(12)
100/100
Last Updated
2023-10-19 (3y ago)
Active Installs
400+
Downloads
12,404
Requires WP
4.0+
Requires PHP
5.6+
Tested up to
WP 6.3.10
Created
2015-10-23 (11y ago)

Tor is an invaluable tool for protecting free-speech, privacy, and preventing surveillance but when abused it can protect the identity of malicious users and make tracking their activities more difficult. “Hackers” might use Tor to run security scans on your website or spam websites with comments and fake registrations. The purpose of this plugin is to give you the power to block certain Tor activity from your WordPress site. Features include: Block Tor users from registering on your site Allow Tor registrations, but flag them for review Block logins from Tor (useful for preventing brute force attacks and securing your admin panel) Block Tor users from posting comments to your site Block spammy pingbacks & trackbacks from Tor IP addresses Block Tor users from your entire WordPress site Permit access after solving a CAPTCHA (requires hCaptcha for WordPress plugin) Real-time blocking using the Tor DNS exit list service Near real time blocking using a cached blocklist which can be updated every 10 minutes or more Custom blocklist support. Block IP addresses or host networks. Statistics to show how many Tor actions have been blocked by this plugin This plugin is compatible with BuddyPress, the popular Login With Ajax plugin, and hCaptcha. If there is a feature missing that you would like, request it! If you opt to use the real-time blocking, each IP address looked up is cached for 5 minutes for efficiency. The Tor IP lists that are downloaded only contain “exit node” IP addresses so it is relatively small and the list is searched using a binary search so the plugin is very fast! This plugin also adds two shortcodes which can be used to display specific content to Tor or non-Tor users. Shortcode usage: [tor_users]Hi, I see you're using Tor. I support privacy and free-speech too! Visitors not using Tor will not see this message.[/tor_users] [non_tor_users]Defend yourself against tracking and surveillance. Circumvent censorship. Visit torproject.org to learn more. Visitors already using Tor will not see this message.[/non_tor_users] Support Tor Tor is a great thing. If you agree, consider volunteering, donating to the Tor project, or expand the Tor network by sponsoring a Tor relay which will be maintained by the plugin author. Support this plugin The author of this plugin values Tor as well as the security of your website. Considerable effort went into the development of this plugin as well as the code and infrastructure that provides you with the up-to-date exit lists. You can support this plugin by installing it, rating it positively, donating to the author, or sponsoring a Tor relay which will be operated by the plugin developer in your honor.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C