WordPress security by component
PublishPress Authors
Plugin description
PublishPress Authors is a WordPress component with 5 published CVE records in this archive. The latest tracked vulnerability was published Mar 25, 2026; the highest CVE/CNA score is 8.8.
Plugin slug:
publishpress-authorsLatest vulnerability
CVE-2026-25309: PublishPress Authors: A security weakness
PublishPress Authors is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 4.10.1.
| Safe version |
|
||
|---|---|---|---|
| Mar 25, 2026 |
CVE-2026-25309
PublishPress Authors: A security weakness
PublishPress Authors is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 4.10.1.
|
4.11.0 |
CVE7.5
NVDPending
|
| Feb 19, 2026 |
CVE-2026-25330
PublishPress Authors: A security weakness
PublishPress Authors is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| May 07, 2025 |
CVE-2025-47496
PublishPress Authors: Filesystem traversal
PublishPress Authors is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE7.5
NVDPending
|
| Mar 15, 2025 |
CVE-2025-26886
PublishPress Authors: SQL injection
PublishPress Authors is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE7.6
NVDPending
|
| Oct 17, 2024 |
CVE-2024-9215
Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors: Privilege escalation or authentication bypass
Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors is affected by privilege escalation or authentication bypass. Exploitation requires at least author-level access. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE8.8
NVDPending
|