WP Adminify <= 4.0.7.7 - Unauthenticated Sensitive Information Exposure via 'get-addons-list' REST API
WP Adminify – White Label WordPress, Admin Menu Editor, Login Customizer
Minimum safe version
4.0.7.8
Update to 4.0.7.8 or later to address 12 fixable vulnerabilities
Latest available4.1.16 ✓
N/A
2026-01-27< 4.0.7.8
Medium 4.3
2025-12-24< 4.0.7
CVE-2025-68592
Medium 5.4
2025-12-24< 4.0.7
CVE-2025-68593
Medium 6.3
2024-10-16< 2.0.5
Freemius SDK <= 2.4.2 - Missing Authorization Checks
Medium 6.4
2024-10-24< 4.0.1.7
CVE-2024-8959
High 7.6
2024-12-28< 3.1.7
WordPress WP Adminify Plugin <= 3.1.6 is vulnerable to SQL Injection
Medium 5.9
2023-10-02< 3.1.8
CVE-2023-44266
Medium 4.8
2023-09-11< 3.1.6
CVE-2023-4060
N/A
2023-07-18< 3.1.4
WordPress WP Adminify – Powerhouse Toolkit for WordPress Dashboard Plugin < 3.1.4 is vulnerable to Cross Site Scripting (XSS)
N/A
2022-03-04< 2.0.5
Freemius SDK <= 2.4.2 - Missing Authorization Checks
N/A
2022-02-28< 2.0.5
WordPress WP Adminify – Powerhouse Toolkit for WordPress Dashboard plugin <= 2.0.4 - Sensitive Information Disclosure vulnerability
N/A
2022-02-28< 2.0.5
WordPress WP Adminify – Powerhouse Toolkit for WordPress Dashboard plugin <= 2.0.4 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability