plugin

Wp Editor Vulnerabilities

10 known security issues reported for the Wp Editor WordPress plugin. Most recent disclosed Apr 30, 2026.

1 critical 5 high 4 medium

Running Wp Editor on your site? Check whether your installed version is affected.

Scan your site free

WP Editor <= 1.2.9.2 - Cross-Site Request Forgery to Remote Code Execution via Plugin and Theme File Editor

high

The WP Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.9.2. This is due to missing nonce verification in the 'add_plugins_page' and 'add_themes_page' functions. This makes it possible for unauthenticated attackers to overwrite arbitrary plugin and theme...

CVSS:
8.8
Affected:
up to 1.2.9.2
Fixed in:
1.2.9.3
Disclosed:
Apr 30, 2026

CVE-2026-3772 on NVD →

WP Editor <= 1.2.9.1 - Authenticated (Administrator+) Directory Traversal to Arbitrary File Read

medium

The WP Editor plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.2.9.1. This makes it possible for authenticated attackers, with Administrator-level access and above, to read arbitrary files on the affected site's server which may reveal sensitive information.

CVSS:
4.9
Affected:
up to 1.2.9.1
Fixed in:
1.2.9.2
Disclosed:
Apr 16, 2025

CVE-2025-3295 on NVD →

WP Editor <= 1.2.9.1 - Authenticated (Administrator+) Directory Traversal to Arbitrary File Update

high

The WP Editor plugin for WordPress is vulnerable to arbitrary file update due to missing file path validation in all versions up to, and including, 1.2.9.1. This makes it possible for authenticated attackers, with Administrator-level access and above, to overwrite arbitrary files on the affected site's server which may...

CVSS:
7.2
Affected:
up to 1.2.9.1
Fixed in:
1.2.9.2
Disclosed:
Apr 16, 2025

CVE-2025-3294 on NVD →

WP Editor <= 1.2.9 - Authenticated (Admin+) PHAR Deserialization

high

The WP Editor plugin for WordPress is vulnerable to deserialization of untrusted input via the 'current_theme_root' parameter in versions up to, and including 1.2.9. This makes it possible for authenticated attackers with administrative privileges to call files using a PHAR wrapper that will deserialize and call arbitr...

CVSS:
7.2
Affected:
up to 1.2.9
Fixed in:
1.2.9.1
Disclosed:
Sep 12, 2024

CVE-2022-2446 on NVD →

WP Editor <= 1.2.8 - Reflected Cross-Site Scripting

medium

The WP Editor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.2.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully t...

CVSS:
6.1
Affected:
up to 1.2.8
Fixed in:
1.2.9
Disclosed:
Mar 26, 2024

CVE-2024-24700 on NVD →

WP Editor <= 1.2.7 - Sensitive Information Exposure via log file

medium

The WP Editor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.7 via the plugin's log file. This makes it possible for unauthenticated attackers to extract sensitive data including configuration information.

CVSS:
5.3
Affected:
up to 1.2.7
Fixed in:
1.2.8
Disclosed:
Feb 12, 2024

CVE-2024-25591 on NVD →

WP Editor <= 1.2.6.3 - Authenticated (Admin+) SQL injection

high

The WP Editor plugin for WordPress is vulnerable to blind SQL Injection via the setting fields in versions up to, and including, 1.2.6.3 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated admin+ attackers to...

CVSS:
7.2
Affected:
up to 1.2.6.3
Fixed in:
1.2.7
Disclosed:
Feb 1, 2021

CVE-2021-24151 on NVD →

WP Editor < 1.2.6 - Incorrect Permission Assignment or Protection

critical

The wp-editor plugin before 1.2.6 for WordPress has incorrect permissions.

CVSS:
9.8
Affected:
up to 1.2.6
Fixed in:
1.2.6
Disclosed:
Jan 15, 2021

CVE-2016-10886 on NVD →

WP Editor <= 1.2.6.2 - Cross-Site Scripting

medium

The wp-editor plugin before 1.2.6.3 for WordPress has multiple XSS issues.

CVSS:
6.1
Affected:
up to 1.2.6.3
Fixed in:
1.2.6.3
Disclosed:
Oct 5, 2016

CVE-2016-10877 on NVD →

WP Editor < 1.2.6 - Cross-Site Request Forgery

high

The WP Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 1.2.6. This is due to missing or incorrect nonce validation on the save_settings() function, in addition to a few other functions. This makes it possible for unauthenticated attackers to modify the plugin's settings and upl...

CVSS:
8.8
Affected:
up to 1.2.6
Fixed in:
1.2.6
Disclosed:
May 13, 2016

CVE-2016-10885 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database