Author Bio Box
Author Bio Box has one disclosed vulnerability in the WordSec catalog, all reported in 2021; it is fixed as of September 2026. Their average CVSS score is 5.5, and the most serious one scores 5.5 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Author Bio Box has a vendor fix available, so running the current release closes it.
All of these findings were reported by Thinkland Security Team. Author Bio Box is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 5.8.15.
CVE-2021-39349Author Bio Box <= 3.3.1 - Authenticated Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Author Bio Box
Author
Claudio Sanches
Display a box with the author’s biography and also social icons in bottom of the post. Contribute You can contribute to the source code in our GitHub page. Credits Initial idea by Gustavo Freitas. License Author Bio Box is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version. Author Bio Box is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details. You should have received a copy of the GNU General Public License along with Author Bio Box. If not, see http://www.gnu.org/licenses/.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C