WP vBulletin SSO Security & Risk Analysis

wordpress.org/plugins/wp-vbulletin-sso

Looking for SSO tool for your WordPress and vBulletin sites?

10 active installs v1.3.5 PHP + WP 4.4+ Updated Unknown
loginregistrationsingle-sign-onssouser-management
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP vBulletin SSO Safe to Use in 2026?

Generally Safe

Score 100/100

WP vBulletin SSO has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The wp-vbulletin-sso plugin v1.3.5 exhibits a mixed security posture. While it demonstrates good practices by exclusively using prepared statements for SQL queries and has no recorded vulnerabilities, significant concerns exist regarding its attack surface and data sanitization. The plugin exposes two AJAX handlers, both lacking authentication checks, creating a direct pathway for unauthorized actions. Furthermore, the taint analysis revealed flows with unsanitized paths, including one of high severity, indicating potential risks of injection attacks if user-supplied data is not properly validated and escaped before being used in file operations or other sensitive contexts.

Despite the absence of historical CVEs, which is a positive indicator, the identified unprotected entry points and unsanitized data flows are critical weaknesses. The high percentage of improperly escaped output also contributes to the overall risk, as it could lead to cross-site scripting (XSS) vulnerabilities. The plugin's strengths lie in its secure SQL handling and clean vulnerability history. However, the identified security flaws, particularly the unprotected AJAX endpoints and taint analysis findings, necessitate careful consideration and remediation to ensure the plugin's overall security. Without addressing these issues, the plugin poses a moderate to high risk, especially in environments where it handles sensitive data or interacts with external systems.

Key Concerns

  • Unprotected AJAX handlers
  • High severity taint flow
  • Unsanitized paths in taint flows
  • Improperly escaped output
Vulnerabilities
None known

WP vBulletin SSO Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP vBulletin SSO Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
14
9 escaped
Nonce Checks
1
Capability Checks
2
File Operations
4
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

39% escaped23 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

4 flows3 with unsanitized paths
manageLogFiles (classes\AdminSettingsPage.php:83)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

WP vBulletin SSO Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_wvsso_check_loginwp-vbulletin-sso.php:152
noprivwp_ajax_wvsso_check_loginwp-vbulletin-sso.php:153
WordPress Hooks 42
actionadmin_menuclasses\AdminSettingsPage.php:26
actioninitclasses\AdminSettingsPage.php:27
actionwp_authenticatewp-vbulletin-sso.php:94
actionpassword_resetwp-vbulletin-sso.php:95
actionwppb_password_resetwp-vbulletin-sso.php:96
actionwp_logoutwp-vbulletin-sso.php:97
actionwp_loginwp-vbulletin-sso.php:98
actionwpmu_new_userwp-vbulletin-sso.php:100
actionuser_registerwp-vbulletin-sso.php:101
actionwppb_signup_userwp-vbulletin-sso.php:104
actionprofile_updatewp-vbulletin-sso.php:108
actionwpmu_delete_userwp-vbulletin-sso.php:110
actiondelete_userwp-vbulletin-sso.php:111
filterwppb_output_fields_filterwp-vbulletin-sso.php:114
filterwppb_signup_user_notification_email_contentwp-vbulletin-sso.php:115
filterwppb_success_email_confirmationwp-vbulletin-sso.php:116
filtermustache_variable_ec_activation_linkwp-vbulletin-sso.php:117
filterwppb_check_form_field_default-usernamewp-vbulletin-sso.php:121
filterregistration_errorswp-vbulletin-sso.php:122
actionadmin_footerwp-vbulletin-sso.php:123
filterwppb_check_form_field_default-passwordwp-vbulletin-sso.php:125
actionwppb_before_register_fieldswp-vbulletin-sso.php:127
actionwppb_before_edit_profile_fieldswp-vbulletin-sso.php:128
actionedit_user_profile_updatewp-vbulletin-sso.php:130
actionwppb_after_sending_emailwp-vbulletin-sso.php:132
actionwppb_register_successwp-vbulletin-sso.php:133
actionlogin_form_registerwp-vbulletin-sso.php:139
actionlogin_form_loginwp-vbulletin-sso.php:142
actionlost_passwordwp-vbulletin-sso.php:145
filterwppb_login_form_argswp-vbulletin-sso.php:149
filterwppb_after_login_redirect_urlwp-vbulletin-sso.php:155
actionlogin_initwp-vbulletin-sso.php:159
actionwp_print_styleswp-vbulletin-sso.php:171
filterlogin_form_bottomwp-vbulletin-sso.php:179
filterwppb_register_activate_user_error_message1wp-vbulletin-sso.php:197
filterwppb_register_activate_user_error_message2wp-vbulletin-sso.php:198
filterwppb_register_activate_user_error_message4wp-vbulletin-sso.php:199
filterwppb_register_activate_user_error_message5wp-vbulletin-sso.php:200
filterwppb_register_failed_user_activationwp-vbulletin-sso.php:201
filteruser_profile_update_errorswp-vbulletin-sso.php:204
actionwppb_after_sending_emailwp-vbulletin-sso.php:569
actioninitwp-vbulletin-sso.php:766
Maintenance & Trust

WP vBulletin SSO Maintenance & Trust

Maintenance Signals

WordPress version tested5.6.17
Last updatedUnknown
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

WP vBulletin SSO Developer Profile

extremeidea

5 plugins · 100 total installs

81
trust score
Avg Security Score
82/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP vBulletin SSO

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-vbulletin-sso/includes/assets/css/style.css
Version Parameters
wp-vbulletin-sso/includes/assets/css/style.css?ver=

HTML / DOM Fingerprints

JS Globals
WVSSO_PRODUCT_NAMEWVSSO_REDIRECT_URL_PARAMWVSSO_REDIRECT_LINK_TEXTWVSSO_ERROR_25_CHARS_TEXTWVSSO_ERROR_ILLEGAL_CHARS_TEXTWVSSO_ERROR_PASS_EQ_USERNAME_TEXT+9 more
FAQ

Frequently Asked Questions about WP vBulletin SSO