← WordPress Vulnerabilities
WordPress security by component

Simple add pages or posts

Simple add pages or posts is a WordPress component with 3 published CVE records in this archive. The latest tracked vulnerability was published Feb 08, 2025; the highest CVE/CNA score is 6.5.

Plugin slug: simple-add-pages-or-posts

CVE-2024-13850: Simple add pages or posts: Cross-site scripting

Simple add pages or posts is affected by cross-site scripting. Exploitation requires at least administrator-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.

PublishedFeb 08, 2025
Safe version guidanceSee mitigation notes
Safe version
Feb 08, 2025 CVE-2024-13850
Simple add pages or posts: Cross-site scripting
Simple add pages or posts is affected by cross-site scripting. Exploitation requires at least administrator-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.5
NVD4.8
Jan 07, 2025 CVE-2024-12288
Simple add pages or posts: Cross-site request forgery
Simple add pages or posts is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE6.1
NVDPending
Aug 14, 2019 CVE-2016-10883
Simple Add Pages Or Posts: Cross-site request forgery
Simple Add Pages Or Posts is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE6.5
NVD6.5