Contentstudio is a content-management and publishing platform whose vulnerability profile centers on authentication and authorization weaknesses, including user-controlled key authorization bypasses, missing authorization checks, and exposure of sensitive information to unauthorized actors. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Contentstudio over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-67910CRITICAL Unrestricted Upload of File with Dangerous Type vulnerability in contentstudio Contentstudio contentstudio allows Upload a Web Shell to a Web Server.This issue affects Contentstudi | Jan 8, 2026 | 9.8 | 34 | NO | NO |
CVE-2023-0558CRITICAL The ContentStudio plugin for WordPress is vulnerable to authorization bypass due to an unsecure token check that is susceptible to type juggling in versions up to, and including, 1 | Jan 27, 2023 | 9.8 | 31 | NO | NO |
CVE-2025-12181HIGH The ContentStudio plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the cstu_update_post() function in all versions up to, and inc | Dec 5, 2025 | 8.8 | 29 | NO | NO |
CVE-2023-0557MEDIUM The ContentStudio plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.2.5. This could allow unauthenticated attackers to obtain | Jan 27, 2023 | 5.3 | 21 | NO | NO |
CVE-2023-0556MEDIUM The ContentStudio plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several functions in versions up to, and including, 1.2.5. This ma | Jan 27, 2023 | 6.5 | 19 | NO | NO |
CVE-2025-13144MEDIUM The ContentStudio plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.7. This is due to missing or insufficient nonce validat | Dec 5, 2025 | 4.3 | 18 | NO | NO |
CVE-2025-49990MEDIUM Missing Authorization vulnerability in contentstudio Contentstudio contentstudio allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Contentstudio: f | Jun 20, 2025 | 5.3 | 17 | NO | NO |
CVE-2025-47692MEDIUM Missing Authorization vulnerability in contentstudio Contentstudio contentstudio allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contents | May 7, 2025 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Contentstudio.
Media articles that mention a CVE ID that affects a product developed by Contentstudio — matched by CVE ID, not by vendor name.