WP-Orphanage Extended
WP-Orphanage Extended has one disclosed vulnerability in the WordSec catalog, all reported in 2024; it is fixed as of September 2026. Their average CVSS score is 8.8, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 1 high.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for WP-Orphanage Extended has a vendor fix available, so running the current release closes it.
All of these findings were reported by SOPROBRO. WP-Orphanage Extended is installed on roughly 100 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2024-11415WP-Orphanage Extended <= 1.2 - Cross-Site Request Forgery to Orphan Account Privilege Escalation
Read the full analysisVulnerability Records

WP-Orphanage Extended
Author
meloniq
Users who have not been assigned any Roles or Capabilities are called ‘orphans’. When using the shared users table trick to link up multiple WordPress installations, users who register on one of your blogs, are not given any privileges on the other blogs in the network. WP-Orphanage is a plugin that automatically adopts your orphan users by promoting them to the role of your choosing. By default it is the same as the default role set in the WP Options. It does it in two ways: Users who try to login to a different blog in the network than the one they signed up on, will be promoted at the time of login. The user won’t even know that it happened. When the admin logs into the blog and views the users page, all orphan users – for that blog – are promoted automatically. By taking a just in time approach, this plugin will not add any noticeable overhead to your WordPress blogs, while providing a seamless experience for the users and administrators. This plugin is a extended version of WP-Orphanage plugin written by Eric Marden
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C