PublishPress develops WordPress plugins focused on content management and scheduling capabilities, with its vulnerability profile centered on authorization and request-validation issues such as cross-site request forgery, improper access control, and unsafe deserialization of untrusted data. These weakness classes are characteristic of web plugins that manage workflow state and user permissions across WordPress multisite environments. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Publishpress over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-25032CRITICAL The PublishPress Capabilities WordPress plugin before 2.3.1, PublishPress Capabilities Pro WordPress plugin before 2.3.1 does not have authorisation and CSRF checks when updating t | Jan 10, 2022 | 9.8 | 46 | NO | YES |
CVE-2022-3366HIGH The PublishPress Capabilities WordPress plugin before 2.5.2, PublishPress Capabilities Pro WordPress plugin before 2.5.2 unserializes the content of imported files, which could lea | Oct 31, 2022 | 7.2 | 24 | NO | NO |
CVE-2026-39482MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PublishPress Post Expirator post-expirator allows DOM-Based XSS.This issue aff | Apr 8, 2026 | 6.5 | 22 | NO | NO |
CVE-2021-24783MEDIUM The Post Expirator WordPress plugin before 2.6.0 does not have proper capability checks in place, which could allow users with a role as low as Contributor to schedule deletion of | Nov 8, 2021 | 6.5 | 22 | NO | NO |
CVE-2025-69361MEDIUM Missing Authorization vulnerability in PublishPress Post Expirator post-expirator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Ex | Jan 6, 2026 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Publishpress.
Media articles that mention a CVE ID that affects a product developed by Publishpress — matched by CVE ID, not by vendor name.