Tooltipy (tooltips for WP)
Tooltipy (tooltips for WP) has 4 disclosed vulnerabilities in the WordSec catalog, reported between 2018 and 2025; 3 are fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 6.3, and the most serious one scores 6.5 out of 10. 2025 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Scripting, behind 3 of the records (75%). Other recurring categories include Cross-Site Request Forgery (CSRF).
3 of the records (75%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2025.
4 independent researchers contributed these findings, one record each. Tooltipy (tooltips for WP) is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
CVE-2025-62917Tooltipy <= 5.5.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Tooltipy (tooltips for WP)
Author
Jamel Zarga
Tooltipy automatically detects keywords in your posts/pages and displays tooltip popups with their definitions. Version 7 is a major architectural rewrite (PHP 8.1+ OOP, Tippy.js rendering) with 100% backward compatibility for existing users (same database options, post meta keys, CSS classes, shortcodes, and hooks). Key Features Auto-detect keywords and display tooltips on hover (Tippy.js) Synonyms support (pipe-separated) Case-sensitive matching option Prefix matching (e.g. “photo” matches “photography”) Glossary shortcode: [tooltip_glossary] (aliases: [kttg_glossary], [tooltipy_glossary]) Manual shortcode: [tooltip] Keyword families / categories AJAX loading of tooltip content YouTube video tooltips Image alt-text tooltips Sidebar widget showing related keywords Extensible addon system Architecture (7.x) PHP 8.1 namespaces under Tooltipy\ Tippy.js bundled locally (no CDN) Full backward compatibility: same option names, post meta keys, hooks
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C