WH Tweaks

WH Tweaks has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 4.4, and the most serious one scores 4.4 out of 10.

The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).

The one issue recorded for WH Tweaks has a vendor fix available, so running the current release closes it.

All of these findings were reported by Muhammad Nur Ibnu Hubab. WH Tweaks is installed on roughly 100 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.

Strategic Overview

Avg CVSSMedium
4.4/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all WH Tweaks vulnerabilities before they are exploited.

Highest severity on recordCVSS 4.4CVE-2025-67630

WH Tweaks <= 1.0.2 - Authenticated (Administrator+) Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

1 records
Plugin Profile
Latestv1.0.3
5.0(1)
100/100
Last Updated
2026-01-07 (8mo ago)
Active Installs
100+
Downloads
4,579
Requires WP
4.0+
Requires PHP
0+
Tested up to
WP 6.9.7
Created
2016-07-06 (10y ago)

Often times, ideas from WordPress Ideas (https://wordpress.org/ideas/) or bugs from WordPress Trac (https://core.trac.wordpress.org/) take years to make it into WordPress Core. Sometimes even if everyone agrees on the fix it still doesn’t get in. This plugin is the temporary patch you’ve been waiting for. Activate any feature you want and disable any you don’t want. Allow excerpts to show links. Obscure login errors so an attacker will not know if a username exists. Hide WordPress version in both meta tags and script inclusions. Make category children highlighted with a subtle gray background. Some added shortcodes. Customize login. Remove emoji scripts and styles. Automatically set the Return-Path to the From address if it’s not already set (Trac #22837). Show private pages in parent dropdowns (Trac #8592). Allow commas in category terms (Trac #14691). Show sidebar from main site in Multisite (Trac #22370). Disable default WordPress REST API endpoints. Remove author pages from public viewing. Redirect user enumeration to 403 Forbidden page. Resolve PHP notices about “ob_end_flush()” (Trac #18525 and #22430). Each of these options can be turned on or off on the Settings -> WH Tweaks page.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C