Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors [publishpress-authors] <= 4.10.1 (unfixed)
unknown
[en] Missing Authorization vulnerability in PublishPress PublishPress Authors publishpress-authors allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PublishPress Authors: from n/a through <= 4.10.1.
- Affected:
- up to 4.10.1
- Fix:
- No patched version reported
- Disclosed:
- Mar 25, 2026
CVE-2026-25309 on NVD →
PublishPress Authors - Broken Access Control vulnerability
high
Broken Access Control vulnerability
- CVSS:
- 7.5
- Affected:
- up to 4.10.1
- Fixed in:
- 4.11.0
- Disclosed:
- Mar 17, 2026
Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors <= 4.10.1 - Missing Authorization
medium
The Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.10.1. This makes it possible for unauthenticated attackers to perform an unautho...
- CVSS:
- 5.3
- Affected:
- up to 4.10.1
- Fixed in:
- 4.11.0
- Disclosed:
- Mar 17, 2026
CVE-2026-25309 on NVD →
Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors [publishpress-authors] <= 4.10.1 (unfixed)
unknown
[en] Missing Authorization vulnerability in PublishPress PublishPress Authors publishpress-authors allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PublishPress Authors: from n/a through <= 4.10.1.
- Affected:
- up to 4.10.1
- Fix:
- No patched version reported
- Disclosed:
- Feb 19, 2026
CVE-2026-25330 on NVD →
PublishPress Authors <= 4.10.1 - Missing Authorization
medium
The Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.10.1. This makes it possible for authenticated attackers, with Contributor-level...
- CVSS:
- 4.3
- Affected:
- up to 4.10.1
- Fixed in:
- 4.11.0
- Disclosed:
- Feb 6, 2026
CVE-2026-25330 on NVD →
PublishPress Authors <= 4.7.5 - Authenticated (Contributor+) Local File Inclusion
high
The PublishPress Authors plugin for WordPress is vulnerable to Local File Inclusion via the filterAuthorBoxHtml() function in versions up to, and including, 4.7.5. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing...
- CVSS:
- 8.8
- Affected:
- up to 4.7.5
- Fixed in:
- 4.7.6
- Disclosed:
- May 7, 2025
CVE-2025-47496 on NVD →
Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors [publishpress-authors] < 4.7.6
unknown
[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PublishPress PublishPress Authors allows PHP Local File Inclusion. This issue affects PublishPress Authors: from n/a through 4.7.5.
- Affected:
- up to 4.7.6
- Fixed in:
- 4.7.6
- Disclosed:
- May 7, 2025
CVE-2025-47496 on NVD →
Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors [publishpress-authors] < 4.7.4
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PublishPress PublishPress Authors allows SQL Injection. This issue affects PublishPress Authors: from n/a through 4.7.3.
- Affected:
- up to 4.7.4
- Fixed in:
- 4.7.4
- Disclosed:
- Mar 15, 2025
CVE-2025-26886 on NVD →
PublishPress Authors <= 4.7.3 - Authenticated (Administrator+) SQL Injection
medium
The PublishPress Authors plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.7.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level acc...
- CVSS:
- 4.9
- Affected:
- up to 4.7.3
- Fixed in:
- 4.7.4
- Disclosed:
- Mar 3, 2025
CVE-2025-26886 on NVD →
Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors [publishpress-authors] < 4.7.2
unknown
[en] The Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress is vulnerable to Insecure Direct Object Reference to Privilege Escalation/Account Takeover in all versions up to, and including, 4.7.1 via the action_edited_author() due to missing validation on the '...
- Affected:
- up to 4.7.2
- Fixed in:
- 4.7.2
- Disclosed:
- Oct 17, 2024
CVE-2024-9215 on NVD →
Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors <= 4.7.1 - Insecure Direct Object Reference to Authenticated (Author+) Arbitrary User Email Update and Account Takeover
high
The Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress is vulnerable to Insecure Direct Object Reference to Privilege Escalation/Account Takeover in all versions up to, and including, 4.7.1 via the action_edited_author() due to missing validation on the 'autho...
- CVSS:
- 8.8
- Affected:
- up to 4.7.1
- Fixed in:
- 4.7.2
- Disclosed:
- Oct 16, 2024
CVE-2024-9215 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database