Known vulnerabilities in Intranet & Private Site – All-In-One Intranet
Turn WordPress into a private intranet in one click. Restrict access to logged-in members, with auto-logout and login redirect, also on multisite.
1Reported vulnerabilities
5.3Highest CVSS score
1.10.0Latest version
4,000+Active installs
What to do now
Update Intranet & Private Site – All-In-One Intranet to 1.9.0 or later.
1 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2026-54837 | Medium | 0.4% | 1.8.1 and earlier | 1.9.0 |
June 18, 2026 |