PLUGIN SECURITY
Is White Label Cms safe?
Customise dashboard panels and branding, hide menus plus lots more.
What this plugin does
- Slug:
white-label-cms - Author: Video User Manuals
- 200000+ active installs
- 94/100 rating (113 reviews on wordpress.org)
- 4836396 all-time downloads
- On WordPress.org since 2010-04-04
adminbrandingcmscustomdashboard
Maintenance status
- Latest known version: 2.7.14
- Last updated: 2026-07-09 4:16am GMT
- Tested up to WordPress: 7.0.4
- Requires PHP: 5.4+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
7 known CVEs on file for White Label Cms. Reported between 2012 and 2026.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-11898 | White Label CMS [white-label-cms] < 2.7.13 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.4 | < 2.7.13 | 2.7.13 | 2026-07-10 | ✓ fixed in latest |
| CVE-2024-43303 | White Label CMS [white-label-cms] < 2.7.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.1 | < 2.7.5 | 2.7.5 | 2024-08-16 | ✓ fixed in latest |
| CVE-2024-4280 | White Label CMS [white-label-cms] < 2.7.4 | Missing Authorization | Medium 5.3 | < 2.7.4 | 2.7.4 | 2024-05-09 | ✓ fixed in latest |
| CVE-2022-4302 | White Label CMS [white-label-cms] < 2.5 | Deserialization of Untrusted Data | High 7.2 | < 2.5 | 2.5 | 2022-12-08 | ✓ fixed in latest |
| CVE-2022-0422 | White Label CMS [white-label-cms] < 2.2.9 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 2.2.9 | 2.2.9 | 2022-02-07 | ✓ fixed in latest |
| — | White Label CMS [white-label-cms] < 1.5.3 | — | Unknown | < 1.5.3 | 1.5.3 | 2015-05-15 | ✓ fixed in latest |
| — | White Label CMS [white-label-cms] < 1.5.3 | — | Unknown | < 1.5.3 | 1.5.3 | 2015-04-29 | ✓ fixed in latest |
| CVE-2012-5387, CVE-2012-5388 | White Label CMS [white-label-cms] < 1.5.1 | Cross-Site Request Forgery (CSRF) | Unknown | < 1.5.1 | 1.5.1 | 2012-10-15 | ✓ fixed in latest |
+ 3 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2012-5388 | White Label CMS [white-label-cms] < 1.5.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Unknown | < 1.5.1 | 1.5.1 | 2012-10-15 | ✓ fixed in latest |
| — | White Label CMS [white-label-cms] < 1.5.3 | — | Unknown | < 1.5.3 | 1.5.3 | — | ✓ fixed in latest |
| — | White Label CMS <= 1.5.2 - Stored XSS | — | Unknown | < 1.5.3 | 1.5.3 | — | ✓ fixed in latest |
How to fix it
Keep White Label Cms updated — 2.7.14 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- List category posts — 80000+ active installs — 94/100 (254) — max PHP 8.4
- Theme My Login — 60000+ active installs — 74/100 (460) — max PHP 8.4
- Cornerstone — 30000+ active installs — 80/100 (6) — max PHP <8.0
- Rich Table of Contents — 20000+ active installs — 82/100 (17) — max PHP <8.0
- Custom Login — 10000+ active installs — 72/100 (97)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.