Known vulnerabilities in WP Super Edit
Get control of the WordPress wysiwyg visual editor and add some functionality with more buttons and custom TinyMCE plugins.
2Reported vulnerabilities
9.3Highest CVSS score
2.5.4Latest version
2,000+Active installs
What to do now
Update WP Super Edit to 2.5.4 or later.
Some of these have no published fix. Update to the latest version and check the vendor advisory.
This plugin has not been updated in over two years. New vulnerabilities may never be fixed. Consider an alternative.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2021-47965 | Critical | 0.6% | 0 to 2.5.4 (inclusive) | — | May 15, 2026 |
| CVE-2025-49948 | Medium | 0.3% | 2.5.4 and earlier | — | July 9, 2025 |