Allows AJAX requests from other sites to integrate content from your site using the CORS standard.
As of April 2026, WP-CORS is a WordPress ajax plugin with 1.0K+ active installations and a 2.3/5 rating from 3 reviews. It has been downloaded 39K+ times in total. Requires WordPress 3.6+ and PHP false+. Available on WordPress.org since 2014. Last updated 2 years ago — may have compatibility concerns. Downloads are down 8% this week. Top alternative: zipaddr-jp.
My use case is to allow content authors to write help pages in WordPress.
This content is fetched and embedded into a single page application hosted on another domain.
AJAX requests to this site from another are typically disallowed by the browser’s security model.
To permit legitimate uses the requesting browser may include an Origin header containing its domain.
This plugin uses the Origin header to decide whether to allow the request or not.
Allowed domains can be specified in the plugin’s Settings page.
Doesn’t work at all
its not working for me.. my website yet giving error cores origin error.
Exactly what i search for. Thankyou 🙂
| WordPress | 3.6+ requiredTested up to 6.2.9 |
| PHP | false+ required |
Tested up to WordPress 6.2.2
Prevent cross-site script injection on Settings page (CVE-2022-47606).
Note this vulnerability may only be exploited if the user is already logged in with Admin privilege.
Plugin data sourced from WordPress.org. Analysis and metrics by PluginSift.