Writeprint Stylometry - Reflected Cross-Site Scripting via 'p' Parameter vulnerability
highReflected Cross-Site Scripting via 'p' Parameter vulnerability
- CVSS:
- 7.1
- Affected:
- up to 0.1
- Fix:
- No patched version reported
- Disclosed:
- Mar 18, 2026
plugin
2 known security issues reported for the Writeprint Stylometry WordPress plugin. Most recent disclosed Mar 18, 2026.
Running Writeprint Stylometry on your site? Check whether your installed version is affected.
Scan your site freeReflected Cross-Site Scripting via 'p' Parameter vulnerability
The Writeprint Stylometry plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'p' GET parameter in all versions up to and including 0.1. This is due to insufficient input sanitization and output escaping in the bjl_wprintstylo_comments_nav() function. The function directly outputs the $_GET['p'...
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free