WP BrowserUpdate
WP BrowserUpdate has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2023; all 2 are fixed as of September 2026. Their average CVSS score is 4.5, and the most serious one scores 4.8 out of 10. 2023 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (50%). Other recurring categories include Cross-Site Scripting.
Every one of the 2 issues recorded for WP BrowserUpdate has a vendor fix available, so running the current release closes all known holes.
All of these findings were reported by qilin_99. WP BrowserUpdate is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2023-28690WP BrowserUpdate <= 4.5 - Authenticated (Admin+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

WP BrowserUpdate
Author
MacSteini
Many users still browse with outdated browsers, often unaware of the risks. Upgrading ensures better security and reliability. This plugin displays a subtle notification prompting visitors to update their browser. Activate the plugin, and it works seamlessly. WP BrowserUpdate is based on the browser-update.org detection logic. The plugin now runs independently from browser-update.org at display time: the visitor-facing notification is served from the plugin’s own bundled runtime files, so sites do not need to load scripts, styles, or default notification links from browser-update.org. browser-update.org remains the credited upstream source for the bundled detection logic, and future runtime refreshes are tracked with source URLs and hashes in the plugin assets. Visit browserupdate.org for more details about the upstream project. Want to help translate this plugin? Visit the WordPress Translation Project. How it works WP BrowserUpdate bundles browser-update.org detection logic for WordPress. After activation, the plugin loads the local notification runtime from the plugin directory and passes your configured browser-version thresholds to those scripts. The notification is shown only when the bundled detection logic matches a browser to your settings. The settings page is available under Settings > WP BrowserUpdate. You can define browser versions for every browser key supported by the bundled browser-update.org runtime, choose where the message appears and which element should contain it, enable testing mode, decide whether mobile or unsupported browsers should be notified, customize links, language and message text, and add trusted custom CSS for the notification. Browser version fields accept major versions such as 115 and positive dotted versions such as 137.0.3912.63. Dotted versions are passed exactly to the bundled runtime instead of being reduced to their major version; exact comparison depends on the bundled browser-update.org logic and the browser key used by that runtime. A value of 0 uses the default bundled outdated-browser detection. Negative whole numbers are passed to the bundled runtime as relative offsets from the current bundled upstream version. Microsoft Edge and Microsoft Internet Explorer have separate settings now. This local runtime design avoids frontend blocking of external script URLs on sites with strict Content Security Policies or tracker blocking. WP BrowserUpdate ships only the local runtime and CSP adapter files needed by the plugin. Important Notice Breaking Changes in Version 6.0 – Requires WordPress 6.0 or newer. – Introduces a new structured settings model to support the browser-update.org customization surface used by WP BrowserUpdate. – Moves the visitor-facing browser-update.org runtime into the plugin package so strict Content Security Policies and tracker blockers no longer need to allow scripts from browser-update.org. – Existing WP BrowserUpdate settings from version 5.x are migrated automatically. Breaking Changes in Version 5.0 – Requires PHP 7.4 or newer. – Ensure your hosting is updated to PHP 7.4 before upgrading to version 5.0 or newer. – Servers running older PHP versions are no longer supported. – If your server is running an earlier PHP version, please download version 4.8.1.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C