plugin

Contentstudio Vulnerabilities

17 known security issues reported for the Contentstudio WordPress plugin. Most recent disclosed Jan 8, 2026.

2 critical 3 high 3 medium

Running Contentstudio on your site? Check whether your installed version is affected.

Scan your site free

ContentStudio [contentstudio] <= 1.3.7 (unfixed)

unknown

[en] Unrestricted Upload of File with Dangerous Type vulnerability in contentstudio Contentstudio contentstudio allows Upload a Web Shell to a Web Server.This issue affects Contentstudio: from n/a through <= 1.3.7.

Affected:
up to 1.3.7
Fix:
No patched version reported
Disclosed:
Jan 8, 2026

CVE-2025-67910 on NVD →

ContentStudio [contentstudio] <= 1.3.7 (unfixed)

unknown

[en] The ContentStudio plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.7. This is due to missing or insufficient nonce validation on the add_cstu_settings function. This makes it possible for unauthenticated attackers to modify plugin settings via a forged requ...

Affected:
up to 1.3.7
Fix:
No patched version reported
Disclosed:
Dec 5, 2025

CVE-2025-13144 on NVD →

ContentStudio [contentstudio] <= 1.3.7 (unfixed)

unknown

[en] The ContentStudio plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the cstu_update_post() function in all versions up to, and including, 1.3.7. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on the...

Affected:
up to 1.3.7
Fix:
No patched version reported
Disclosed:
Dec 5, 2025

CVE-2025-12181 on NVD →

ContentStudio <= 1.3.7 - Authenticated (Author+) Arbitrary File Upload

high

The ContentStudio plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the cstu_update_post() function in all versions up to, and including, 1.3.7. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on the affe...

CVSS:
8.8
Affected:
up to 1.3.7
Fixed in:
1.4.0
Disclosed:
Dec 4, 2025

CVE-2025-12181 on NVD →

ContentStudio <= 1.3.7 - Cross-Site Request Forgery to Settings Update

medium

The ContentStudio plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.7. This is due to missing or insufficient nonce validation on the add_cstu_settings function. This makes it possible for unauthenticated attackers to modify plugin settings via a forged request g...

CVSS:
4.3
Affected:
up to 1.3.7
Fixed in:
1.4.0
Disclosed:
Dec 4, 2025

CVE-2025-13144 on NVD →

ContentStudio [contentstudio] <= 1.3.4 (unfixed)

unknown

[en] Missing Authorization vulnerability in contentstudio ContentStudio allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects ContentStudio: from n/a through 1.3.4.

Affected:
up to 1.3.4
Fix:
No patched version reported
Disclosed:
Jun 20, 2025

CVE-2025-49990 on NVD →

ContentStudio <= 1.3.7 - Missing Authorization

medium

The ContentStudio plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.3.7. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 1.3.7
Fixed in:
1.4.0
Disclosed:
Jun 19, 2025

CVE-2025-49990 on NVD →

ContentStudio <= 1.3.5 - Missing Authorization

medium

The ContentStudio plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.3.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 1.3.5
Fixed in:
1.3.7
Disclosed:
May 7, 2025

CVE-2025-47692 on NVD →

ContentStudio [contentstudio] <= 1.3.3 (unfixed)

unknown

[en] Missing Authorization vulnerability in contentstudio ContentStudio allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ContentStudio: from n/a through 1.3.3.

Affected:
up to 1.3.3
Fix:
No patched version reported
Disclosed:
May 7, 2025

CVE-2025-47692 on NVD →

ContentStudio <= 1.2.5 - Authorization Bypass

high

The ContentStudio plugin for WordPress is vulnerable to authorization bypass due to an unsecure token check that is susceptible to type juggling in versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers to execute functions intended for use by users with proper API keys.

CVSS:
8.2
Affected:
up to 1.2.5
Fixed in:
1.2.6
Disclosed:
Jan 27, 2023

CVE-2023-0558 on NVD →

ContentStudio <= 1.2.5 - Information Exposure

high

The ContentStudio plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.2.5. This could allow unauthenticated attackers to obtain a nonce needed for the creation of posts.

CVSS:
7.5
Affected:
up to 1.2.5
Fixed in:
1.2.6
Disclosed:
Jan 27, 2023

CVE-2023-0557 on NVD →

ContentStudio [contentstudio] < 1.2.6

unknown

[en] The ContentStudio plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several functions in versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers to obtain the blog metadata (via the function cstu_get_metadata) that includes the plugin...

Affected:
up to 1.2.6
Fixed in:
1.2.6
Disclosed:
Jan 27, 2023

CVE-2023-0556 on NVD →

ContentStudio [contentstudio] < 1.2.6

unknown

[en] The ContentStudio plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.2.5. This could allow unauthenticated attackers to obtain a nonce needed for the creation of posts.

Affected:
up to 1.2.6
Fixed in:
1.2.6
Disclosed:
Jan 27, 2023

CVE-2023-0557 on NVD →

ContentStudio [contentstudio] < 1.2.6

unknown

[en] The ContentStudio plugin for WordPress is vulnerable to authorization bypass due to an unsecure token check that is susceptible to type juggling in versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers to execute functions intended for use by users with proper API keys.

Affected:
up to 1.2.6
Fixed in:
1.2.6
Disclosed:
Jan 27, 2023

CVE-2023-0558 on NVD →

ContentStudio <= 1.2.5 - Missing Authorization

critical

The ContentStudio plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several functions in versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers to obtain the blog metadata (via the function cstu_get_metadata) that includes the plugin's co...

CVSS:
9.8
Affected:
up to 1.2.5
Fixed in:
1.2.6
Disclosed:
Jan 6, 2023

CVE-2023-0556 on NVD →

ContentStudio <= 1.1.8 - Missing Authorization

critical

The ContentStudio plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the cstu_set_token functions in versions up to, and including, 1.1.8. This makes it possible for unauthenticated attackers to set the plugin's API token (via cstu_set_token), which allows further actions...

CVSS:
9.8
Affected:
up to 1.1.8
Fixed in:
1.1.9
Disclosed:
Dec 7, 2022

ContentStudio [contentstudio] < 1.1.9

unknown

The ContentStudio plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the cstu_set_token functions in versions up to, and including, 1.1.8. This makes it possible for unauthenticated attackers to set the plugin's API token (via cstu_set_token), which allows further actions...

Affected:
up to 1.1.9
Fixed in:
1.1.9
Disclosed:
Dec 7, 2022

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database