WP Editor

Vulnerabilities 14Slug wp-editorLatest version 1.2.9.3WordPress.org →

Minimum safe version

1.2.9.3

Update to 1.2.9.3 or later to address 14 fixable vulnerabilities

Latest available1.2.9.3
High 7.2
2025-04-17< 1.2.9.2

WP Editor <= 1.2.9.1 - Authenticated (Administrator+) Directory Traversal to Arbitrary File Update

Medium 4.9
2025-04-17< 1.2.9.2

WordPress WP Editor Plugin <= 1.2.9.1 is vulnerable to Directory Traversal

N/A
2016-10-05< 1.2.6.3

WordPress Editor Plugin <= 1.2.6.2 - Multiple Cross Site Scripting

N/A
2017-05-12< 1.2.6

WordPress WP Editor plugin <= 1.2.5.3 - Authenticated File Modification Vulnerability

N/A
2017-05-12< 1.2.6

WordPress WP Editor plugin <= 1.2.5.3 - Authenticated Arbitrary File Upload vulnerability

N/A
2021-02-02< 1.2.7

WordPress WP Editor plugin <= 1.2.6.3 - SQL injection (SQLi) vulnerability

Critical 9.8
2021-01-15< 1.2.6

WP Editor < 1.2.6 - Incorrect Permission Assignment or Protection