Content Audit
Content Audit has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2014 and 2017; all 2 are fixed as of September 2026. Their average CVSS score is 6.7, and the most serious one scores 7.2 out of 10. Severity breakdown: 0 critical and 1 high.
The most common weakness is Cross-Site Scripting, behind 1 of the records (50%). Other recurring categories include SQL Injection.
Every one of the 2 issues recorded for Content Audit has a vendor fix available, so running the current release closes all known holes.
All of these findings were reported by Mallory Adams. Content Audit is installed on roughly 80 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 5.2.26.
CVE-2014-5389Content Audit <= 1.6.0 - Authenticated (Admin+) SQL Injection
Read the full analysisVulnerability Records
Content Audit
Author
Stephanie Leary
Lets you create a content inventory right in the WordPress Edit screens, similar to the process you might use to assess your site’s content in a spreadsheet. You can mark content as redundant, outdated, trivial, or in need of a review for SEO or style. These content status labels work just like categories, so you can remove the built-in ones and add your own if you like. You can also assign a content owner (distinct from the original author) and keep internal notes. The IDs are revealed on the Edit screens so you can keep track of your content even if you change titles and permalinks. The plugin supports custom post types as well as posts, pages, and media files. There’s an Overview report under the Dashboard menu that shows you which posts/pages/attachments/etc. need attention, sorted by user. This screen also lets you export a CSV file of the audit report. The plugin creates three new filters on the Edit screens: author, content owner, and content status. This should make it easy to narrow your focus to just a few pages at a time. You can display the audit details to logged-in editors on the front end if you want, either above or below the content. You can style the audit message with custom CSS. New: you can now clear data from past audits and start over! Translations If you would like to send me a translation, please write to me through my contact page. Let me know which plugin you’ve translated and how you would like to be credited. I will write you back so you can attach the files in your reply. Notes Filter reference ‘content_audit_notes’ filters the public display of the notes field ‘content_audit_dashboard_get_posts_args’ filters the get_posts() arguments for the Dashboard widget ‘content_audit_dashboard_output’ filters the table output of the Dashboard widget ‘content_audit_dashboard_congrats’ filters the congratulations message of the Dashboard widget ‘content_audit_csv_filename’ filters the file name of the CSV download ‘content_audit_csv_header_data’ filters the header label array in the CSV download ‘content_audit_csv_row_data’ filters the contents of each row (as an array) in the CSV download
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C