Known vulnerabilities in WP Editor
WP Editor is a plugin for WordPress that replaces the default plugin and theme editors as well as the page/post editor.
10Reported vulnerabilities
9.8Highest CVSS score
1.2.9.3Latest version
20,000+Active installs
What to do now
Update WP Editor to 1.2.9.3 or later.
10 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2021-24151 | High | 0.8% | Before 1.2.7 | 1.2.7 |
January 16, 2024 |
| CVE-2016-10886 | Critical | 2.0% | Before 1.2.6 | 1.2.6 |
August 14, 2019 |
| CVE-2016-10885 | High | 0.7% | Before 1.2.6 | 1.2.6 |
August 14, 2019 |
| CVE-2026-3772 | High | 0.2% | 0 to 1.2.9.2 (inclusive) | 1.2.9.3 |
May 1, 2026 |
| CVE-2025-3294 | High | 0.9% | Before 1.2.9.2 | 1.2.9.2 |
April 17, 2025 |
| CVE-2022-2446 | High | 0.6% | Before 1.2.9.1 | 1.2.9.1 |
September 13, 2024 |
| CVE-2016-10877 | Medium | 0.9% | Before 1.2.6.3 | 1.2.6.3 |
August 12, 2019 |
| CVE-2024-24700 | Medium | 0.4% | 1.2.8 and earlier | 1.2.9 |
March 26, 2024 |
| CVE-2024-25591 | Medium | 0.5% | 1.2.7 and earlier | 1.2.8 |
February 12, 2024 |
| CVE-2025-3295 | Medium | 0.5% | Before 1.2.9.2 | 1.2.9.2 |
April 17, 2025 |