Pricing
Solutions
WordPress security
Instantly fix and mitigate vulnerabilities
Plugin auditing
Paid auditing for WordPress vendors
Managed VDP
Start a security program for your plugins
Bug Bounty
Join the community and earn bounties
Enterprise API
At scale monitoring and vPatching for hosts
Vulnerability database
The latest WordPress security intelligence
Login
Start trial
Profile Builder
Cozmoslabs
Developer
3.14.9
Latest version
50,000
Installations
20 hours ago
Last updated
WordPress Plugin
No VDP
See changelog
Claim ownership
Report vulnerability
Vulnerabilities
Vulnerability history
0 present
23 fixed
9 Mitigation rules
Authenticated (Subscriber+) Stored Cross-Site Scripting vulnerability
<= 3.14.3
Aug 16, 2025
Content Spoofing Vulnerability
<= 3.13.8
Jun 5, 2025
Authenticated (Contributor+) Stored Cross-Site Scripting via user_meta and compare Shortcodes vulnerability
<= 3.13.8
Jun 3, 2025
Admin+ Stored Cross Site Scripting vulnerability
<= 3.12.0
May 19, 2025
Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode vulnerability
<= 3.13.6
Apr 15, 2025
Unauthenticated Stored Cross-Site Scripting vulnerability
<= 3.12.9
Jan 7, 2025
Unauthenticated Media Upload vulnerability
< 3.11.8
Jul 29, 2024
Bypass Vulnerability vulnerability
<= 3.11.2
Apr 5, 2024
Missing Authorization to Plugin Settings Change vulnerability
<= 3.10.8
Jan 16, 2024
Insecure Direct Object Reference to Sensitive Information Exposure via user_meta Shortcode vulnerability
<= 3.10.7
Jan 8, 2024
Cross Site Request Forgery (CSRF) vulnerability
<= 3.10.3
Nov 8, 2023
Missing Authorization to Initial Page Creation vulnerability
< 3.9.8
Aug 9, 2023
Insecure Password Reset Mechanism vulnerability
<= 3.9.0
Apr 27, 2023
Sensitive Information Disclosure via Shortcode vulnerability
<= 3.9.0
Feb 14, 2023
Cross-Site Request Forgery (CSRF) vulnerability
<= 3.6.0
Sep 29, 2022
Stored Cross-Site Scripting (XSS) vulnerability
<= 3.6.7
Mar 9, 2022
Reflected Cross-Site Scripting (XSS) vulnerability
<= 3.6.1
Feb 17, 2022
Authenticated Stored Cross-Site Scripting (XSS) vulnerability
<= 3.4.7
Jun 30, 2021
Authenticated Blind SQL Injection (SQLi) vulnerability
<= 3.3.2
Dec 2, 2020
User Registration With Administrator Role vulnerability
<= 3.1.0
Feb 10, 2020
Reflected Cross Site Scripting
<= 2.4.1
Jul 13, 2016
Privilege Escalation
<= 2.4.0
Jul 8, 2016
BYPASS
<= 1.1.59
Aug 1, 2014