plugin

Story Chief Vulnerabilities

9 known security issues reported for the Story Chief WordPress plugin. Most recent disclosed Aug 15, 2025.

1 critical 2 medium

Running Story Chief on your site? Check whether your installed version is affected.

Scan your site free

StoryChief <= 1.0.42 - Unauthenticated Arbitrary File Upload

critical

The StoryChief plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 1.0.42. This vulnerability occurs through the /wp-json/storychief/webhook REST-API endpoint that does not have sufficient filetype validation. This makes it possible for unauthenticated attackers to upload...

CVSS:
9.8
Affected:
up to 1.0.42
Fixed in:
1.0.43
Disclosed:
Aug 15, 2025

CVE-2025-7441 on NVD →

StoryChief <= 1.0.30 - Reflected Cross-Site Scripting

medium

The plugin in versions up to 1.0.30 does not sanitise or escape its tab parameter in the Settings page before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue.

CVSS:
6.1
Affected:
up to 1.0.30
Fixed in:
1.0.31
Disclosed:
Aug 2, 2021

StoryChief <= 1.0.30 - Authenticated Stored Cross-Site Scripting

medium

The plugin does not sanitise and escape its StoryChief Key setting before outputting it in an attribute, leading to an Authenticated Stored Cross-Site Scripting issue

CVSS:
6.1
Affected:
up to 1.0.30
Fixed in:
1.0.31
Disclosed:
Aug 2, 2021

StoryChief [story-chief] < 1.0.31

unknown

Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress StoryChief plugin (versions <= 1.0.30).

Affected:
up to 1.0.31
Fixed in:
1.0.31
Disclosed:
Aug 2, 2021

StoryChief [story-chief] < 1.0.31

unknown

The plugin in versions up to 1.0.30 does not sanitise or escape its tab parameter in the Settings page before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue.

Affected:
up to 1.0.31
Fixed in:
1.0.31
Disclosed:
Aug 2, 2021

StoryChief [story-chief] < 1.0.31

unknown

The plugin does not sanitise and escape its StoryChief Key setting before outputting it in an attribute, leading to an Authenticated Stored Cross-Site Scripting issue

Affected:
up to 1.0.31
Fixed in:
1.0.31
Disclosed:
Aug 2, 2021

StoryChief [story-chief] < 1.0.31

unknown

The plugin does not sanitise and escape its StoryChief Key setting before outputting it in an attribute, leading to an Authenticated Stored Cross-Site Scripting issue

Affected:
up to 1.0.31
Fixed in:
1.0.31

StoryChief [story-chief] < 1.0.31

unknown

The plugin does not sanitise or escape its tab parameter in the Settings page before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue

Affected:
up to 1.0.31
Fixed in:
1.0.31

StoryChief [story-chief] <= 1.0.42 (unfixed)

unknown
Affected:
up to 1.0.42
Fix:
No patched version reported

CVE-2025-7441 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database