plugin

Zotpress Vulnerabilities

19 known security issues reported for the Zotpress WordPress plugin. Most recent disclosed Jun 10, 2025.

2 critical 6 medium

Running Zotpress on your site? Check whether your installed version is affected.

Scan your site free

ZotPress <= 7.3.15 - Authenticated (Author+) Stored Cross-Site Scripting via 'nickname'

medium

The Zotpress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘nickname’ parameter in all versions up to, and including, 7.3.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary...

CVSS:
6.4
Affected:
up to 7.3.15
Fixed in:
7.4
Disclosed:
Jun 10, 2025

CVE-2025-4666 on NVD →

Zotpress [zotpress] < 7.3.13

unknown

[en] The Zotpress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Zotpress_process_accounts_AJAX function in all versions up to, and including, 7.3.12. This makes it possible for authenticated attackers, with Contributor-level access and above, to reset t...

Affected:
up to 7.3.13
Fixed in:
7.3.13
Disclosed:
Nov 5, 2024

CVE-2024-7429 on NVD →

Zotpress <= 7.3.12 - Missing Authorization

medium

The Zotpress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Zotpress_process_accounts_AJAX function in all versions up to, and including, 7.3.12. This makes it possible for authenticated attackers, with Contributor-level access and above, to reset the pl...

CVSS:
4.3
Affected:
up to 7.3.12
Fixed in:
7.3.13
Disclosed:
Nov 4, 2024

CVE-2024-7429 on NVD →

Zotpress [zotpress] < 7.3.11

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Katie Seaborn Zotpress allows Stored XSS.This issue affects Zotpress: from n/a through 7.3.10.

Affected:
up to 7.3.11
Fixed in:
7.3.11
Disclosed:
Oct 5, 2024

CVE-2024-47621 on NVD →

Zotpress <= 7.3.10 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Zotpress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.3.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that w...

CVSS:
6.4
Affected:
up to 7.3.10
Fixed in:
7.3.11
Disclosed:
Sep 30, 2024

CVE-2024-47621 on NVD →

Zotpress [zotpress] < 7.3.10

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Katie Seaborn Zotpress allows Stored XSS.This issue affects Zotpress: from n/a through 7.3.9.

Affected:
up to 7.3.10
Fixed in:
7.3.10
Disclosed:
May 8, 2024

CVE-2024-34569 on NVD →

Zotpress <= 7.3.9 - Authenticated (Contributor+) Cross-Site Scripting

medium

The Zotpress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all versions up to, and including, 7.3.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access...

CVSS:
6.4
Affected:
up to 7.3.9
Fixed in:
7.3.10
Disclosed:
May 7, 2024

CVE-2024-34569 on NVD →

Zotpress [zotpress] < 7.3.8

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Katie Seaborn Zotpress.This issue affects Zotpress: from n/a through 7.3.7.

Affected:
up to 7.3.8
Fixed in:
7.3.8
Disclosed:
Mar 29, 2024

CVE-2024-30488 on NVD →

Zotpress <= 7.3.7 - Authenticated (Contributor+) SQL Injection

critical

The Zotpress plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 7.3.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above,...

CVSS:
9.9
Affected:
up to 7.3.7
Fixed in:
7.3.8
Disclosed:
Mar 28, 2024

CVE-2024-30488 on NVD →

Zotpress [zotpress] < 7.3.5

unknown

[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Katie Seaborn Zotpress plugin <= 7.3.4 versions.

Affected:
up to 7.3.5
Fixed in:
7.3.5
Disclosed:
Oct 31, 2023

CVE-2023-46313 on NVD →

Zotpress <= 7.3.4 - Reflected Cross-Site Scripting via 'PHP_SELF'

medium

The Zotpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'PHP_SELF' in versions up to, and including, 7.3.4 due to insufficient input sanitization and output escaping. On certain configurations including Apache+modPHP, this makes it possible for unauthenticated attackers to inject arbitrary...

CVSS:
6.1
Affected:
up to 7.3.4
Fixed in:
7.3.5
Disclosed:
Sep 10, 2023

CVE-2023-46313 on NVD →

Zotpress [zotpress] < 7.3.5

unknown

The Zotpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'PHP_SELF' in versions up to, and including, 7.3.4 due to insufficient input sanitization and output escaping. On certain configurations including Apache+modPHP, this makes it possible for unauthenticated attackers to inject arbitrary...

Affected:
up to 7.3.5
Fixed in:
7.3.5
Disclosed:
Sep 10, 2023

Zotpress [zotpress] < 7.3.4

unknown

[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Katie Seaborn Zotpress plugin <= 7.3.3 versions.

Affected:
up to 7.3.4
Fixed in:
7.3.4
Disclosed:
Jun 12, 2023

CVE-2023-32961 on NVD →

Zotpress <= 7.3.3 - Reflected Cross-Site Scripting

medium

The Zotpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 7.3.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses a...

CVSS:
5.4
Affected:
up to 7.3.3
Fixed in:
7.3.4
Disclosed:
May 16, 2023

CVE-2023-32961 on NVD →

Zotpress < 6.1.3 - SQL Injection

critical

Zotpress plugin for WordPress before 6.1.3 has SQLi in zp_get_account().

CVSS:
9.8
Affected:
up to 6.1.3
Fixed in:
6.1.3
Disclosed:
Oct 6, 2016

CVE-2016-1000217 on NVD →

Zotpress [zotpress] < 6.1.3

unknown

[en] Zotpress plugin for WordPress SQLi in zp_get_account()

Affected:
up to 6.1.3
Fixed in:
6.1.3
Disclosed:
Oct 6, 2016

CVE-2016-1000217 on NVD →

Zotpress [zotpress] < 4.5

unknown

This WordPress Zotpress plugin is prone to an SQL injection. This vulnerability allows an attacker to modify data, alter queries to the application SQL database, compromise the access and application or exploit hidden vulnerabilities in the underlying database. Upgrade the plugin.

Affected:
up to 4.5
Fixed in:
4.5
Disclosed:
Sep 4, 2011

Zotpress [zotpress] < 4.4.1

unknown

The Zotpress WordPress plugin was affected by a SQL Injection security vulnerability.

Affected:
up to 4.4.1
Fixed in:
4.4.1

Zotpress [zotpress] <= 7.3.15 (unfixed)

unknown
Affected:
up to 7.3.15
Fix:
No patched version reported

CVE-2025-4666 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database