← WordPress Vulnerabilities
WordPress security by component

PublishPress Authors

PublishPress Authors is a WordPress component with 5 published CVE records in this archive. The latest tracked vulnerability was published Mar 25, 2026; the highest CVE/CNA score is 8.8.

Plugin slug: publishpress-authors

CVE-2026-25309: PublishPress Authors: A security weakness

PublishPress Authors is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 4.10.1.

PublishedMar 25, 2026
Known safe version4.11.0
Safe version
Mar 25, 2026 CVE-2026-25309
PublishPress Authors: A security weakness
PublishPress Authors is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 4.10.1.
4.11.0
CVE7.5
NVDPending
Feb 19, 2026 CVE-2026-25330
PublishPress Authors: A security weakness
PublishPress Authors is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
May 07, 2025 CVE-2025-47496
PublishPress Authors: Filesystem traversal
PublishPress Authors is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE7.5
NVDPending
Mar 15, 2025 CVE-2025-26886
PublishPress Authors: SQL injection
PublishPress Authors is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.6
NVDPending
Oct 17, 2024 CVE-2024-9215
Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors: Privilege escalation or authentication bypass
Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors is affected by privilege escalation or authentication bypass. Exploitation requires at least author-level access. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE8.8
NVDPending