WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Draft – Tailwind CSS for WordPress.

Add Tailwind CSS to WordPress, in seconds.

12Reported vulnerabilities
7.2Highest CVSS score
3.0.9Latest version
600+Active installs

What to do now

Update Draft – Tailwind CSS for WordPress. to 3.5.5 or later. 11 of these have a fixed version available. Updating resolves them.

Plugin last updated: September 23, 2024 / Tested up to WordPress: 6.6.7 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2021-24891 Medium 6.1 25.1% After 1.5.0, before 3.1.4
3.2.0 up to (but not including) 3.4.8
3.1.4 November 23, 2021
CVE-2023-0329 High 7.2 19.7% Before 3.12.2 3.12.2 May 30, 2023
CVE-2022-4953 Medium 6.1 3.4% Before 3.5.5 3.5.5 August 14, 2023
CVE-2020-20634 Medium 6.5 1.0% 2.9.5 and earlier 2.9.6 August 21, 2020
CVE-2021-24205 Medium 5.4 0.8% Before 3.1.4 3.1.4 April 5, 2021
CVE-2020-36703 Medium 5.4 0.5% 2.9.7 and earlier 2.9.8 June 7, 2023
CVE-2021-24206 Medium 5.4 0.7% Before 3.1.4 3.1.4 April 5, 2021
CVE-2021-24204 Medium 5.4 0.7% Before 3.1.4 3.1.4 April 5, 2021
CVE-2021-24203 Medium 5.4 0.7% Before 3.1.4 3.1.4 April 5, 2021
CVE-2021-24202 Medium 5.4 0.7% Before 3.1.4 3.1.4 April 5, 2021
CVE-2021-24201 Medium 5.4 0.7% Before 3.1.4 3.1.4 April 5, 2021
CVE-2025-58033 Medium 4.4 0.2% 3.0.9 and earlier September 22, 2025

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.