Auto Prune Posts
Auto Prune Posts has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2025; all 3 are fixed as of September 2026. Their average CVSS score is 4.7, and the most serious one scores 5.4 out of 10. 2025 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 2 of the records (67%). Other recurring categories include Cross-Site Scripting.
Every one of the 3 issues recorded for Auto Prune Posts has a vendor fix available, so running the current release closes all known holes.
3 independent researchers contributed these findings, one record each. Auto Prune Posts is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
CVE-2023-27423Auto Prune Posts <= 1.8.0 - Cross-Site Request Forgery via admin_menu
Read the full analysisVulnerability Records
Auto Prune Posts
Author
ramon fincken
Auto deletes expires (prunes) posts or pages after a certain amount of time. On a per category basis (single category, or all at once). Handy if you want to have posts with a limited timeframe such as offers, coupons etc.. Posts will auto delete on a per category basis: single category OR all categories at once. All (custom)post types are supported. (CPT support) Will also trash post attachments. Sends notification to site admin (can be turned off). No cronjob needed 🙂 Coding by: MijnPress.nl Mastodon profile More plugins Idea by Nostromo.nl Donate https://donate.ramonfincken.com/
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C