codoc
codoc has one disclosed vulnerability in the WordSec catalog, all reported in 2024; it is fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for codoc has a vendor fix available, so running the current release closes it.
All of these findings were reported by Majed Refaea. codoc is installed on roughly 2,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
CVE-2024-37961codoc <= 0.9.51.12 - Reflected Cross-Site Scripting
Read the full analysisVulnerability Records

codoc
Author
codoc
codoc is a simple and powerful WordPress paywall plugin that enables creators to sell paid articles, offer Reader Plans (Subscription / Membership), and accept tips. Originally built for Japanese creators, codoc is also fully compatible with users in the US/EU. Payment is processed via Stripe, and buyers worldwide can purchase using a valid credit card (currency: JPY/USD/EUR). After setup, the plugin adds a codoc block※ to the post editor. ※Compatible with both Gutenberg and the Classic Editor (TinyMCE). How it works Content placed below the codoc block becomes the paid section and is hidden from non-buyers. Content placed above remains freely available. The codoc block: – displays the purchase interface – handles buyer authentication – allows per-article settings such as price or Reader Plan availability – all revenue/customer management is available on codoc.jp More details : codoc for WordPress Help center : FAQ Features Article paywall One-time purchases Reader Plans (Subscription / Membership) Tipping support Stripe payments (Credit card / Apple Pay / Google Pay / Konibini) Gutenberg & Classic Editor support Featured image support Revenue & customer management via codoc.jp Insert custom HTML before/after codoc tags CSS override support Safe authentication & Stripe-level fraud prevention
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C