WP Post Author <= 3.9.1 - Authenticated (Author+) SQL Injection
medium
The WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars plugin for WordPress is vulnerable to generic SQL Injection via the 'wpma_metabox_authors_list' parameter in all versions up to, and including, 3.9.1 due to insufficient escaping on the user supplied parameter and lack of sufficient prepa...
- CVSS:
- 6.5
- Affected:
- up to 3.9.1
- Fixed in:
- 3.10.0
- Disclosed:
- Aug 4, 2026
CVE-2026-11977 on NVD →
WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars <= 3.9.1 - Authenticated (Contributor+) SQL Injection
medium
The WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.9.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible f...
- CVSS:
- 6.5
- Affected:
- up to 3.9.1
- Fixed in:
- 3.10.0
- Disclosed:
- Jun 26, 2026
CVE-2026-57643 on NVD →
Freemius <= 2.10.1 - Reflected DOM-Based Cross-Site Scripting via url Parameter
medium
Multiple plugins and/or themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the url parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succe...
- CVSS:
- 6.1
- Affected:
- up to 3.8.3
- Fixed in:
- 3.8.4
- Disclosed:
- Apr 30, 2026
CVE-2024-13362 on NVD →
WP Post Author – Boost Your Blog's Engagement with Author Box, Social Links, Co-Authors, Guest Authors, Post Rating System, and Custom User Registration Form Builder [wp-post-author] < 3.8.3
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AF themes WP Post Author allows SQL Injection.This issue affects WP Post Author: from n/a through 3.8.2.
- Affected:
- up to 3.8.3
- Fixed in:
- 3.8.3
- Disclosed:
- Jan 2, 2025
CVE-2024-56247 on NVD →
WP Post Author <= 3.8.2 - Authenticated (Administrator+) SQL Injection
medium
The WP Post Author plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access an...
- CVSS:
- 4.9
- Affected:
- up to 3.8.2
- Fixed in:
- 3.8.3
- Disclosed:
- Dec 30, 2024
CVE-2024-56247 on NVD →
WP Post Author – Boost Your Blog's Engagement with Author Box, Social Links, Co-Authors, Guest Authors, Post Rating System, and Custom User Registration Form Builder [wp-post-author] < 3.8.2
unknown
[en] The WP Post Author – Boost Your Blog's Engagement with Author Box, Social Links, Co-Authors, Guest Authors, Post Rating System, and Custom User Registration Form Builder plugin for WordPress is vulnerable to time-based SQL Injection via the linked_user_id parameter in all versions up to, and including, 3.8.1...
- Affected:
- up to 3.8.2
- Fixed in:
- 3.8.2
- Disclosed:
- Oct 12, 2024
CVE-2024-8757 on NVD →
Boost Your Blog's Engagement with WP Post Author <= 3.8.1 - Authenticated (Administrator+) SQL Injection
high
The WP Post Author – Boost Your Blog's Engagement with Author Box, Social Links, Co-Authors, Guest Authors, Post Rating System, and Custom User Registration Form Builder plugin for WordPress is vulnerable to time-based SQL Injection via the linked_user_id parameter in all versions up to, and including, 3.8.1 due t...
- CVSS:
- 7.2
- Affected:
- up to 3.8.1
- Fixed in:
- 3.8.2
- Disclosed:
- Oct 11, 2024
CVE-2024-8757 on NVD →
WP Post Author – Boost Your Blog's Engagement with Author Box, Social Links, Co-Authors, Guest Authors, Post Rating System, and Custom User Registration Form Builder [wp-post-author] < 3.6.8
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in AF themes WP Post Author allows Stored XSS.This issue affects WP Post Author: from n/a through 3.6.7.
- Affected:
- up to 3.6.8
- Fixed in:
- 3.6.8
- Disclosed:
- Jul 22, 2024
CVE-2024-37101 on NVD →
WP Post Author <= 3.6.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The WP Post Author plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.6.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages t...
- CVSS:
- 6.4
- Affected:
- up to 3.6.7
- Fixed in:
- 3.6.8
- Disclosed:
- Jun 20, 2024
CVE-2024-37101 on NVD →
WP Post Author – Enhance Your Posts with the Author Bio, Co-Authors, Guest Authors, and Post Rating System, including User Registration Form Builder <= 3.6.4 - Missing Authorization to Rating Manipulation
medium
The WP Post Author – Enhance Your Posts with the Author Bio, Co-Authors, Guest Authors, and Post Rating System, including User Registration Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.6.4. This makes it po...
- CVSS:
- 4.3
- Affected:
- up to 3.6.4
- Fixed in:
- 3.6.5
- Disclosed:
- May 6, 2024
CVE-2024-34387 on NVD →
WP Post Author – Enhance Your Posts with the Author Bio, Co-Authors, Guest Authors, and Post Rating System, including User Registration Form Builder <= 3.7.4 - Missing Authorization
medium
The WP Post Author plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the awpa_pro_api_post_rating_review() function in all versions up to, and including, 3.7.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to leave reviews on pr...
- CVSS:
- 4.3
- Affected:
- up to 3.7.4
- Fixed in:
- 3.7.5
- Disclosed:
- May 6, 2024
CVE-2024-34389 on NVD →
WP Post Author – Boost Your Blog's Engagement with Author Box, Social Links, Co-Authors, Guest Authors, Post Rating System, and Custom User Registration Form Builder [wp-post-author] < 3.6.5
unknown
[en] Missing Authorization vulnerability in AF themes WP Post Author.This issue affects WP Post Author: from n/a through 3.6.4.
- Affected:
- up to 3.6.5
- Fixed in:
- 3.6.5
- Disclosed:
- May 6, 2024
CVE-2024-34387 on NVD →
WP Post Author – Boost Your Blog's Engagement with Author Box, Social Links, Co-Authors, Guest Authors, Post Rating System, and Custom User Registration Form Builder [wp-post-author] < 3.7.5
unknown
[en] Missing Authorization vulnerability in AF themes WP Post Author.This issue affects WP Post Author: from n/a through 3.6.4.
- Affected:
- up to 3.7.5
- Fixed in:
- 3.7.5
- Disclosed:
- May 6, 2024
CVE-2024-34389 on NVD →
WP Post Author <= 3.2.3 - Privilege Escalation
critical
The WP Post Author plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.2.3. This is due to insufficient controls on the /set-user-data REST API endpoint. This makes it possible for authenticated attackers to set their user role to administrator and gain complete access to the...
- CVSS:
- 9.8
- Affected:
- up to 3.2.3
- Fixed in:
- 3.3.0
- Disclosed:
- Jun 28, 2023
WP Post Author – Boost Your Blog's Engagement with Author Box, Social Links, Co-Authors, Guest Authors, Post Rating System, and Custom User Registration Form Builder [wp-post-author] < 3.3.0
unknown
Update the WordPress WP Post Author plugin to the latest available version (at least 3.3.0).
An unknown person discovered and reported this Privilege Escalation vulnerability in WordPress WP Post Author Plugin. This could allow a malicious actor to escalate their low privileged account to something with higher privileg...
- Affected:
- up to 3.3.0
- Fixed in:
- 3.3.0
- Disclosed:
- Jun 28, 2023
WP Post Author – Boost Your Blog's Engagement with Author Box, Social Links, Co-Authors, Guest Authors, Post Rating System, and Custom User Registration Form Builder [wp-post-author] < 3.3.0
unknown
The WP Post Author plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.2.3. This is due to insufficient controls on the /set-user-data REST API endpoint. This makes it possible for authenticated attackers to set their user role to administrator and gain complete access to the...
- Affected:
- up to 3.3.0
- Fixed in:
- 3.3.0
- Disclosed:
- Jun 28, 2023
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database