Known vulnerabilities in WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars
WP Post Author is the ultimate solution for an Author Box, Multiple Authors, Guest Authors, and Local Avatars. Easily manage Author Bios, Co-authors, …
8Reported vulnerabilities
9.8Highest CVSS score
3.10.0Latest version
10,000+Active installs
What to do now
Update WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars to 3.10.0 or later.
8 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| WF-155e3de1-e115-4683-bb4d-a0c5667dc3d3 | Critical | — | 3.2.3 and earlier | 3.3.0 |
June 28, 2023 |
| CVE-2024-8757 | High | 0.5% | 0 to 3.8.1 (inclusive) 0 to 3.8.1 (inclusive) |
3.8.2 |
October 12, 2024 |
| CVE-2026-11977 | Medium | 0.2% | 0 to 3.9.1 (inclusive) | 3.10.0 |
August 5, 2026 |
| CVE-2026-57643 | Medium | 0.4% | 3.9.1 and earlier | 3.10.0 |
June 26, 2026 |
| CVE-2024-37101 | Medium | 0.3% | 3.6.7 and earlier | 3.6.8 |
June 20, 2024 |
| CVE-2024-56247 | Medium | 0.5% | 3.8.2 and earlier | 3.8.3 |
December 30, 2024 |
| CVE-2024-34387 | Medium | 0.4% | 3.6.4 and earlier | 3.6.5 |
May 6, 2024 |
| CVE-2024-34389 | Medium | 0.4% | 3.7.4 and earlier | 3.7.5 |
May 6, 2024 |