Author Bio Box

Author Bio Box has one disclosed vulnerability in the WordSec catalog, all reported in 2021; it is fixed as of September 2026. Their average CVSS score is 5.5, and the most serious one scores 5.5 out of 10.

The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).

The one issue recorded for Author Bio Box has a vendor fix available, so running the current release closes it.

All of these findings were reported by Thinkland Security Team. Author Bio Box is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 5.8.15.

Strategic Overview

Avg CVSSMedium
5.5/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Author Bio Box vulnerabilities before they are exploited.

Highest severity on recordCVSS 5.5CVE-2021-39349

Author Bio Box <= 3.3.1 - Authenticated Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

1 records
Author Bio Box banner
Latestv3.4.1

Author Bio Box

Claudio Sanches

Author

Claudio Sanches

4.8(17)
96/100
Last Updated
2021-11-04 (5y ago)
Active Installs
1,000+
Downloads
84,526
Requires WP
4.6+
Requires PHP
0+
Tested up to
WP 5.8.15
Created
2011-10-05 (15y ago)

Display a box with the author’s biography and also social icons in bottom of the post. Contribute You can contribute to the source code in our GitHub page. Credits Initial idea by Gustavo Freitas. License Author Bio Box is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version. Author Bio Box is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details. You should have received a copy of the GNU General Public License along with Author Bio Box. If not, see http://www.gnu.org/licenses/.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C