Classic Editor +
Classic Editor + has one disclosed vulnerability in the WordSec catalog, all reported in 2022; it is fixed as of September 2026. Their average CVSS score is 8.8, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 1 high.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for Classic Editor + has a vendor fix available, so running the current release closes it.
All of these findings were reported by Jan w Oleju. Classic Editor + is installed on roughly 40,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
Classic Editor Addon < 2.6.4 - Cross-Site Request Forgery
Read the full analysisVulnerability Records

Classic Editor +
Author
Pieter Bos
GDPR-compliant: does not collect any user data The free “Classic Editor +” plugin is targeted at everyone who does not want to use the WP Block Editor (Gutenberg), introduced in WordPress 5.0. Install it now on sites and the UX remains the same as you are used to without redundant styling being added to the frontend of your site! What’s New: Removes WP Patterns This plugin simply disables the WP Block Editor, removes any and all styling from both front- and backend and disables the block editor for widgets too. And if WooCommerce and/or WPML are installed on the site, “Classic Editor +” removes the block styles of those plugins too. There are no Settings, it simply does what it says on the label. Therefore I highly recommend installing this “Classic Editor +” plugin. I support this plugin exclusively through Github. Therefore, if you have any questions, need help and/or want to make a feature request, please open an issue here. You can also browse through open and closed issues to find what you are looking for and perhaps even help others. Thanks for your understanding and cooperation. If you like the “Classic Editor +” plugin, please consider leaving a review. Thanks! “Classic Editor +” by Pieter Bos and Greg Schoppe.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C