
Webling Security & Risk Analysis
wordpress.org/plugins/weblingAnmeldeformulare und Mitgliederdaten aus der Vereinssoftware webling.eu auf deiner Webseite anzeigen.
Is Webling Safe to Use in 2026?
Mostly Safe
Score 79/100Webling is generally safe to use. 1 past CVE were resolved. Keep it updated.
The 'webling' plugin v3.9.1 presents a mixed security posture. While it demonstrates some good practices like a significant percentage of SQL queries using prepared statements and a decent number of nonce and capability checks, there are several concerning areas. The presence of the `unserialize` function is a significant risk, as it can lead to Remote Code Execution if misused with untrusted input. Furthermore, the static analysis reveals a REST API route exposed without permission callbacks, creating an unprotected entry point into the plugin's functionality. The taint analysis further amplifies these concerns, showing four flows with unsanitized paths, all categorized as high severity. This suggests potential vulnerabilities where user input might not be adequately validated or escaped, leading to data leakage or manipulation. The vulnerability history, while not indicating critical or high severity past issues, does show a medium severity Cross-site Scripting vulnerability from April 2025 that remains unpatched. This persistent vulnerability, coupled with the new high-severity taint flows and the unprotected REST API endpoint, indicates a need for immediate attention and remediation to strengthen the plugin's overall security.
Key Concerns
- Unprotected REST API route
- High severity unsanitized taint flows
- Dangerous function 'unserialize' used
- Unpatched medium severity CVE
- Low percentage of properly escaped output
Webling Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Webling <= 3.9.0 - Authenticated (Administrator+) Stored Cross-Site Scripting
Webling Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Webling Attack Surface
REST API Routes 1
Shortcodes 2
WordPress Hooks 13
Maintenance & Trust
Webling Maintenance & Trust
Maintenance Signals
Community Trust
Webling Alternatives
VereinOnline.org
vereinonline
Zeigt VereinOnline-Inhalte in WordPress an. http://www.vereinonline.org/
Dr. Flex
dr-flex
Das offizielle Dr. Flex® Wordpress Plugin zur einfachen Einbindung des Dr. Flex® Buchungstools auf Ihrer Website.
easyVerein
easyverein
Das offizielle easyVerein Plugin für WordPress.
Vereinsantrag Formular
vereinsantrag-formular
Bindet Onlineformulare für Mitgliedsanträge, Änderungen und Kündigungen auf Vereinswebsites ein – responsiv und datenschutzkonform.
Microtango
microtango
Microtango WordPress integration. This plugin requires a Microtango subscription. It loads data from the Microtango REST API and renders it on your si …
Webling Developer Profile
1 plugin · 500 total installs
How We Detect Webling
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/webling/css/admin.css/wp-content/plugins/webling/js/admin.js/wp-content/plugins/webling/js/jquery-ui-1.12.1.custom/jquery-ui.min.css/wp-content/plugins/webling/js/admin.jswebling/css/admin.css?pluginver=webling/js/admin.js?pluginver=webling/js/jquery-ui-1.12.1.custom/jquery-ui.min.css?pluginver=HTML / DOM Fingerprints
webling-memberlistwebling-memberwebling-form-field<!-- START Webling Memberlist --><!-- END Webling Memberlist --><!-- START Webling Form --><!-- END Webling Form -->+1 moredata-webling-list-iddata-webling-member-iddata-webling-field-idwebling_admin_ajax_objectwebling_memberlist_data/wp-json/webling/v1/memberimage<div class="webling-memberlist"><form class="webling-form" method="post">