Medium 5.5
2025-07-15< 3.9.3
WordPress Companion Auto Update Plugin <= 3.9.2 is vulnerable to Cross Site Scripting (XSS)
Minimum safe version
3.9.3
Update to 3.9.3 or later to address 6 fixable vulnerabilities
WordPress Companion Auto Update Plugin <= 3.9.2 is vulnerable to Cross Site Scripting (XSS)
Companion Auto Update <= 3.3.5 - Authenticated (Admin+) SQL Injection
Companion Auto Update <= 3.3.5 - Authenticated SQL Injection
WordPress Companion Auto Update plugin <=2.9.3 - Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) Vulnerabilities
CVE-2018-20973
CVE-2018-20972