PLUGIN SECURITY
Is Dynamic Widgets safe?
Dynamic Widgets gives you full control on which pages a widget will display. It lets you dynamicly show or hide widgets on WordPress pages.
What this plugin does
- Slug:
dynamic-widgets - Author: Kalmang
- 10000+ active installs
- 94/100 rating (109 reviews on wordpress.org)
- 1024712 all-time downloads
- On WordPress.org since 2010-01-17
conditionDynamiclogicruleswidget
Maintenance status
- Latest known version: 1.6.6
- Last updated: 2026-02-12 10:01am GMT
- Tested up to WordPress: 6.9.7
- Requires PHP: 5.2.7+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
5 known CVEs on file for Dynamic Widgets. Reported between 2012 and 2024.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2024-51669 | Dynamic Widgets [dynamic-widgets] < 1.6.5 | Cross-Site Request Forgery (CSRF) | Medium 4.3 | < 1.6.5 | 1.6.5 | 2024-11-01 | ✓ fixed in latest |
| CVE-2021-24933 | Dynamic Widgets [dynamic-widgets] < 1.6 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 1.6 | 1.6 | 2021-12-28 | ✓ fixed in latest |
| — | Dynamic Widgets [dynamic-widgets] < 1.5.11 | — | Unknown | < 1.5.11 | 1.5.11 | 2015-11-22 | ✓ fixed in latest |
| CVE-2015-10100 | Dynamic Widgets [dynamic-widgets] < 1.5.11 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | Critical 9.8 | < 1.5.11 | 1.5.11 | 2015-10-14 | ✓ fixed in latest |
| CVE-2015-9437, CVE-2015-9436 | Dynamic Widgets [dynamic-widgets] < 1.5.11 | Cross-Site Request Forgery (CSRF) | Medium 6.5 | < 1.5.11 | 1.5.11 | 2015-08-11 | ✓ fixed in latest |
| CVE-2015-9436 | Dynamic Widgets [dynamic-widgets] < 1.5.11 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 1.5.11 | 1.5.11 | 2015-08-11 | ✓ fixed in latest |
| — | Dynamic Widgets [dynamic-widgets] < 1.5.2 | — | Unknown | < 1.5.2 | 1.5.2 | 2012-05-15 | ✓ fixed in latest |
| — | Dynamic Widgets [dynamic-widgets] < 1.5.2 | — | Unknown | < 1.5.2 | 1.5.2 | 2012-05-15 | ✓ fixed in latest |
+ 2 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| — | Dynamic Widgets [dynamic-widgets] < 1.5.2 | — | Unknown | < 1.5.2 | 1.5.2 | — | ✓ fixed in latest |
| — | Dynamic Widgets <= 1.5.1 - Cross-Site Scripting (XSS) | — | Unknown | < 1.5.2 | 1.5.2 | — | ✓ fixed in latest |
How to fix it
Keep Dynamic Widgets updated — 1.6.6 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Dynamic Conditions — 60000+ active installs — 96/100 (114) — max PHP 8.4
- Login or Logout Menu Item — 20000+ active installs — 96/100 (23) — max PHP 8.4
- WP Display Header — 7000+ active installs — 90/100 (27) — max PHP 8.4
- JC Submenu — 4000+ active installs — 92/100 (49)
- Dynamic Year Block — 2000+ active installs — 100/100 (8)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.