WH Tweaks
WH Tweaks has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 4.4, and the most serious one scores 4.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for WH Tweaks has a vendor fix available, so running the current release closes it.
All of these findings were reported by Muhammad Nur Ibnu Hubab. WH Tweaks is installed on roughly 100 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2025-67630WH Tweaks <= 1.0.2 - Authenticated (Administrator+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records
WH Tweaks
Author
webheadcoder
Often times, ideas from WordPress Ideas (https://wordpress.org/ideas/) or bugs from WordPress Trac (https://core.trac.wordpress.org/) take years to make it into WordPress Core. Sometimes even if everyone agrees on the fix it still doesn’t get in. This plugin is the temporary patch you’ve been waiting for. Activate any feature you want and disable any you don’t want. Allow excerpts to show links. Obscure login errors so an attacker will not know if a username exists. Hide WordPress version in both meta tags and script inclusions. Make category children highlighted with a subtle gray background. Some added shortcodes. Customize login. Remove emoji scripts and styles. Automatically set the Return-Path to the From address if it’s not already set (Trac #22837). Show private pages in parent dropdowns (Trac #8592). Allow commas in category terms (Trac #14691). Show sidebar from main site in Multisite (Trac #22370). Disable default WordPress REST API endpoints. Remove author pages from public viewing. Redirect user enumeration to 403 Forbidden page. Resolve PHP notices about “ob_end_flush()” (Trac #18525 and #22430). Each of these options can be turned on or off on the Settings -> WH Tweaks page.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C