Known Vulnerabilities for WP Post Author by AF Themes
Listed below are 10 of the newest known vulnerabilities associated with "WP Post Author" by "AF Themes".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-40229 json | Helpy contains a stored cross-site scripting vulnerability in the post author display logic. Any registered user can persist ... | Not Provided | 2026-04-29 | 2026-04-29 |
| CVE-2026-5711 json | The Post Blocks & Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sliderStyle' block attribu... | Not Provided | 2026-04-08 | 2026-04-09 |
| CVE-2026-4341 json | The Prime Slider – Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'follow_u... | Not Provided | 2026-04-08 | 2026-04-08 |
| CVE-2026-4336 json | The Ultimate FAQ Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via FAQ content in all versions ... | Not Provided | 2026-04-09 | 2026-04-09 |
| CVE-2026-4300 json | The Robo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Loading Label' setting in all ver... | Not Provided | 2026-04-08 | 2026-04-08 |
| CVE-2026-4006 json | The Simple Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'display_name' post meta (Cus... | Not Provided | 2026-03-19 | 2026-04-08 |
| CVE-2026-3651 json | The Build App Online plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0.23. ... | Not Provided | 2026-03-21 | 2026-04-08 |
| CVE-2026-3396 json | WCAPF – WooCommerce Ajax Product Filter plugin is vulnerable to time-based SQL Injection via the 'post-author' parameter in... | Not Provided | 2026-04-08 | 2026-04-08 |
| CVE-2026-3350 json | The Image Alt Text Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post title in all versio... | Not Provided | 2026-03-21 | 2026-04-08 |
| CVE-2026-2879 json | The GetGenie plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.3... | Not Provided | 2026-03-13 | 2026-04-08 |