
RDP Wiki Embed Security & Risk Analysis
wordpress.org/plugins/rdp-wiki-embedRDP Wiki Embed lets you embed content from MediaWiki sites.
Is RDP Wiki Embed Safe to Use in 2026?
Use With Caution
Score 63/100RDP Wiki Embed has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The 'rdp-wiki-embed' plugin v1.2.20 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by utilizing prepared statements for all SQL queries and implementing capability checks for some operations. There are no detected critical or high severity taint flows, and the overall attack surface through AJAX and REST API is zero, which is excellent. However, significant concerns arise from the 1 unpatched medium severity CVE, which indicates a known historical weakness that remains unresolved. The plugin also shows a substantial proportion of improperly escaped output (45%), suggesting a potential for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not handled carefully in the remaining unescaped outputs. The absence of nonce checks, especially in conjunction with potential XSS risks, is a worrying sign for CSRF vulnerabilities. The plugin's past vulnerability history, specifically related to CSRF, further exacerbates these concerns.
While the plugin has no direct exploitable entry points without authentication in its current state, the combination of an unpatched CVE, a high percentage of unescaped output, and a lack of nonce checks presents a tangible risk. The unpatched CVE is the most immediate and critical concern, as it signifies a known, exploitable flaw. The unescaped output and missing nonce checks create an environment where new vulnerabilities could be introduced or exploited more easily, especially by attackers leveraging the historical CSRF trend. The plugin needs immediate attention to address the unpatched vulnerability and to improve output escaping and implement nonce checks to achieve a more robust security posture.
Key Concerns
- Unpatched Medium CVE exists
- Significant unescaped output detected
- No nonce checks implemented
RDP Wiki Embed Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
RDP Wiki Embed <= 1.2.20 - Cross-Site Request Forgery
RDP Wiki Embed Code Analysis
SQL Query Safety
Output Escaping
RDP Wiki Embed Attack Surface
Shortcodes 1
WordPress Hooks 13
Scheduled Events 1
Maintenance & Trust
RDP Wiki Embed Maintenance & Trust
Maintenance Signals
Community Trust
RDP Wiki Embed Alternatives
Wiki Embed
wiki-embed
Wiki Embed lets you embed mediawiki pages in to your site, sites like Wikipedia
WP Wiki Tooltip
wp-wiki-tooltip
Adds explaining tooltips querying their content from a MediaWiki installation, e.g. Wikipedia.org.
Wiki Append
wiki-append
Append a mediawiki page at the end of the regular wordpress page.
Wikiembedder
wikiembedder
Embed MediaWiki in a wordpress site and allow users to navigate the wiki without leaving your wordpress page.
WP-MarkupCollection
wp-markupcollection
This plugin allows you to write posts using Markdown, DokuWiki, MediaWiki, reStructuredText, textile, HatenaSyntax, BBcode, etc.
RDP Wiki Embed Developer Profile
2 plugins · 410 total installs
How We Detect RDP Wiki Embed
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/rdp-wiki-embed/css/rdpWE.css/wp-content/plugins/rdp-wiki-embed/js/rdpWE.js/wp-content/plugins/rdp-wiki-embed/js/rdpWE.admin.js/wp-content/plugins/rdp-wiki-embed/css/rdpWE.admin.css/wp-content/plugins/rdp-wiki-embed/css/simple_html_dom.css/wp-content/plugins/rdp-wiki-embed/css/rdpWE.css?ver=/wp-content/plugins/rdp-wiki-embed/js/rdpWE.js?ver=/wp-content/plugins/rdp-wiki-embed/js/rdpWE.admin.js?ver=/wp-content/plugins/rdp-wiki-embed/css/rdpWE.admin.css?ver=/wp-content/plugins/rdp-wiki-embed/css/simple_html_dom.css?ver=HTML / DOM Fingerprints
rdp-wiki-embed-contentrdp-wiki-embed-sourcerdp-wiki-embed-title<!-- BEGIN WIKI EMBED --><!-- END WIKI EMBED -->data-wiki-embed-shortcodedata-wiki-urldata-wiki-titledata-wiki-embed-optionsrdpWEConfigrdpWEInstance/wp-json/rdp-wiki-embed/v1/content[rdp-wiki-embed[/rdp-wiki-embed]