
WebinarPress – Webinar System for WordPress Security & Risk Analysis
wordpress.org/plugins/wp-webinarsystemSupercharge your website with our powerful webinar plugin! Host engaging live webinars and run automated evergreen webinars effortlessly.
Is WebinarPress – Webinar System for WordPress Safe to Use in 2026?
High Risk
Score 32/100WebinarPress – Webinar System for WordPress carries significant security risk with 10 known CVEs, 5 still unpatched. Consider switching to a maintained alternative.
The wp-webinarsystem plugin exhibits a concerning security posture, despite some positive code signals. While the majority of SQL queries and output operations are well-handled, a significant number of AJAX handlers (126) lack authentication checks, creating a substantial attack surface that could be exploited by unauthenticated users. The presence of the `unserialize` function, even if not directly flagged by taint analysis, warrants caution due to its potential for deserialization vulnerabilities if misused with untrusted data. The plugin's history of 10 known CVEs, with 5 currently unpatched and a significant portion being high or medium severity, paints a picture of recurring security weaknesses. Common vulnerability types like Missing Authorization, SSRF, Open Redirect, XSS, and CSRF indicate a pattern of insecure handling of user input and insufficient access controls. The recent vulnerability in 2025 suggests ongoing issues despite previous fixes. Overall, while some code hygiene is present, the extensive unprotected entry points and the troubling vulnerability history outweigh these strengths, indicating a high-risk plugin.
Key Concerns
- Large attack surface without auth checks
- Dangerous function: unserialize detected
- 5 unpatched CVEs detected
- 2 high severity unpatched CVEs
- 8 medium severity unpatched CVEs
- Flows with unsanitized paths
- Missing nonce checks (5)
- Missing capability checks (41, though some may be intended)
WebinarPress – Webinar System for WordPress Security Vulnerabilities
CVEs by Year
Severity Breakdown
10 total CVEs
WebinarPress <= 1.33.28 - Missing Authorization
WebinarPress <= 1.33.27 - Authenticated (Administrator+) Server-Side Request Forgery
WebinarPress <= 1.33.27 - Open Redirect
WebinarPress <= 1.33.27 - Authenticated (Administrator+) Stored Cross-Site Scripting
WebinarPress <= 1.33.27 - Missing Authorization
WordPress Webinar Plugin – WebinarPress <= 1.33.24 - Missing Authorization to Authenticated (Subscriber+) Webinar Updates
WordPress Webinar Plugin – WebinarPress <= 1.33.24 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Creation
WebinarPress <= 1.33.20 - Cross-Site Request Forgery
WordPress Webinar Plugin – WebinarPress <= 1.33.20 - Cross-Site Request Forgery
WebinarPress <= 1.33.9 - Reflected Cross-Site Scripting
WebinarPress – Webinar System for WordPress Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
WebinarPress – Webinar System for WordPress Attack Surface
AJAX Handlers 126
Shortcodes 12
WordPress Hooks 59
Scheduled Events 3
Maintenance & Trust
WebinarPress – Webinar System for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
WebinarPress – Webinar System for WordPress Alternatives
ON24 Webcast Embed
on24-webcast-embed
A plugin to embed ON24 webcasts using an iframe.
Instant Indexing for Google
fast-indexing-api
A very efficient yet simple plugin to take care of your indexing woos and helps get your content crawled by search bots instantly.
Embed Plus for YouTube Gallery, Livestream and Lazy Loading with Facades
youtube-embed-plus
A multi-featured plugin to embed YouTube in WordPress. Embed a video, YouTube channel gallery, playlist, or YouTube livestream. Defer JavaScript too!
All-in-One Video Gallery
all-in-one-video-gallery
The ultimate video player & video gallery plugin for YouTubers, Video Bloggers, Course Creators, Podcasters, and anyone embedding videos on websites.
Video Conferencing with Zoom
video-conferencing-with-zoom-api
Gives you the power to manage Zoom Meetings, Zoom Webinars, Recordings, Reports and create users directly from your WordPress dashboard.
WebinarPress – Webinar System for WordPress Developer Profile
1 plugin · 1K total installs
How We Detect WebinarPress – Webinar System for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-webinarsystem/wpws-js/build/main.css/wp-content/plugins/wp-webinarsystem/wpws-js/build/main.js/wp-content/plugins/wp-webinarsystem/includes/js/polyfill.min.jswpws-js/build/main.jsincludes/js/polyfill.min.jsjs/registration.jswp-webinarsystem/wpws-js/build/main.css?ver=wp-webinarsystem/wpws-js/build/main.js?ver=wp-webinarsystem/includes/js/polyfill.min.js?ver=wp-webinarsystem/js/registration.js?ver=HTML / DOM Fingerprints
data-wswbn-editor-placeholder___wpws___wpwsRegistrationWidgetsWithTriggers/wp-json/wpws-api/[webinarsystem_registration][webinarsystem_login][wpws_registration][webinarpress_registration]