High 8.8
2026-05-01< 1.2.9.3
CVE-2026-3772
Minimum safe version
1.2.9.3
Update to 1.2.9.3 or later to address 14 fixable vulnerabilities
CVE-2026-3772
WP Editor <= 1.2.9.1 - Authenticated (Administrator+) Directory Traversal to Arbitrary File Update
WordPress WP Editor Plugin <= 1.2.9.1 is vulnerable to Directory Traversal
CVE-2022-2446
CVE-2024-24700
CVE-2024-25591
CVE-2021-24151
WordPress Editor Plugin <= 1.2.6.2 - Multiple Cross Site Scripting
WordPress WP Editor plugin <= 1.2.5.3 - Authenticated File Modification Vulnerability
WordPress WP Editor plugin <= 1.2.5.3 - Authenticated Arbitrary File Upload vulnerability
WordPress WP Editor plugin <= 1.2.6.3 - SQL injection (SQLi) vulnerability
CVE-2016-10877
WP Editor < 1.2.6 - Incorrect Permission Assignment or Protection
CVE-2016-10885