PLUGIN SECURITY
Is Vk All In One Expansion Unit safe?
This plug-in is an integrated plug-in with a variety of features that make it powerful your web site.
What this plugin does
- Slug:
vk-all-in-one-expansion-unit - Author: Hidekazu Ishikawa
- 100000+ active installs
- 80/100 rating (7 reviews on wordpress.org)
- 9231893 all-time downloads
- On WordPress.org since 2015-06-30
facebook page plugingoogle analyticsog tagsrelated postssitemap
Maintenance status
- Latest known version: 9.120.0
- Last updated: 2026-08-24 6:30pm GMT
- Tested up to WordPress: 7.1
- Requires PHP: 7.4+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
14 known CVEs on file for Vk All In One Expansion Unit. Reported between 2023 and 2026.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-39483 | VK All in One Expansion Unit [vk-all-in-one-expansion-unit] < 9.113.4 | — | Medium 6.5 | < 9.113.4 | 9.113.4 | 2026-03-23 | ✓ fixed in latest |
| CVE-2025-11737 | VK All in One Expansion Unit [vk-all-in-one-expansion-unit] < 9.112.4 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 9.112.4 | 9.112.4 | 2026-02-17 | ✓ fixed in latest |
| CVE-2025-11267 | VK All in One Expansion Unit [vk-all-in-one-expansion-unit] < 9.112.2 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) | Medium 6.4 | < 9.112.2 | 9.112.2 | 2025-11-17 | ✓ fixed in latest |
| CVE-2025-11265 | VK All in One Expansion Unit [vk-all-in-one-expansion-unit] < 9.112.2 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) | Medium 6.4 | < 9.112.2 | 9.112.2 | 2025-11-17 | ✓ fixed in latest |
| CVE-2024-52268 | VK All in One Expansion Unit [vk-all-in-one-expansion-unit] < 9.100.1.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.8 | < 9.100.1.0 | 9.100.1.0 | 2024-11-13 | ✓ fixed in latest |
| CVE-2024-37956 | VK All in One Expansion Unit [vk-all-in-one-expansion-unit] < 9.99.2.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 9.99.2.0 | 9.99.2.0 | 2024-07-10 | ✓ fixed in latest |
| CVE-2024-2093 | VK All in One Expansion Unit [vk-all-in-one-expansion-unit] < 9.96.0.0 | Exposure of Sensitive Information to an Unauthorized Actor | Medium 5.3 | < 9.96.0.0 | 9.96.0.0 | 2024-03-26 | ✓ fixed in latest |
| CVE-2024-2170 | VK All in One Expansion Unit [vk-all-in-one-expansion-unit] < 9.97.0.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 9.97.0.0 | 9.97.0.0 | 2024-03-25 | ✓ fixed in latest |
+ 7 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2023-28367 | VK All in One Expansion Unit [vk-all-in-one-expansion-unit] < 9.88.2.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 9.88.2.0 | 9.88.2.0 | 2023-05-23 | ✓ fixed in latest |
| CVE-2023-27926 | VK All in One Expansion Unit [vk-all-in-one-expansion-unit] < 9.88.2.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 9.88.2.0 | 9.88.2.0 | 2023-05-09 | ✓ fixed in latest |
| — | VK All in One Expansion Unit [vk-all-in-one-expansion-unit] < 9.87.1.0 | — | Unknown | < 9.87.1.0 | 9.87.1.0 | 2023-02-23 | ✓ fixed in latest |
| CVE-2023-0937 | VK All in One Expansion Unit [vk-all-in-one-expansion-unit] < 9.87.1.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 9.87.1.0 | 9.87.1.0 | 2023-02-22 | ✓ fixed in latest |
| CVE-2023-0230 | VK All in One Expansion Unit [vk-all-in-one-expansion-unit] < 9.86.0.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 9.86.0.0 | 9.86.0.0 | 2023-02-03 | ✓ fixed in latest |
| CVE-2023-0937 | VK All in One Expansion Unit < 9.87.1.0 - Reflected XSS | — | Unknown | < 9.87.1.0 | 9.87.1.0 | — | ✓ fixed in latest |
| CVE-2023-27923, CVE-2023-27925, CVE-2023-27926, CVE-2023-28367 | VK All in One Expansion Unit < 9.88.2 - Multiple Stored XSS | — | Unknown | < 9.88.2 | 9.88.2 | — | ✓ fixed in latest |
How to fix it
Keep Vk All In One Expansion Unit updated — 9.120.0 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) — 2000000+ active installs — 90/100 (3148) — max PHP 8.4
- GTM4WP – A Google Tag Manager (GTM) plugin for WordPress — 700000+ active installs — 90/100 (154) — max PHP 8.4
- WP Statistics – Simple, privacy-friendly Google Analytics alternative — 600000+ active installs — 82/100 (757) — max PHP <8.0
- GA Google Analytics – Connect Google Analytics to WordPress — 400000+ active installs — 98/100 (158) — max PHP 8.4
- ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) — 300000+ active installs — 50/100 (1547)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.