ContentMX Content Publisher
ContentMX Content Publisher has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2025; all 2 are fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10. 2025 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (50%). Other recurring categories include Missing Authorization.
Every one of the 2 issues recorded for ContentMX Content Publisher has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. ContentMX Content Publisher is installed on roughly 100 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2025-9889ContentMX Content Publisher <= 1.0.6 - Cross-Site Request Forgery
Read the full analysisVulnerability Records
ContentMX Content Publisher
Author
ContentMX
This plugin connects your WordPress blog/website with your ContentMX account allowing you to publish authorized content from your favorite vendors and manufacturers directly to WordPress. This plug-in works securely with ContentMX co-branded platforms such as Microsoft DMC (Digital Marketing Content OnDemand), TD SYNNEX DEMANDSolv, and Arrow’s Curated Content. Please note, this plugin relies on a third-party connection with https://contentmx.com. The plugin will initially use a secure token to create a connection to your account on contentmx.com. Once established this secure connection will be used to publish content you choose to publish to your WordPress blog from your ContentMX account. You can terminate this connection at any time within the plugin administration panel, in your contentMX account, or by deactivating the plugin. ContentMX Terms & Conditions: https://www.contentmx.com/terms/ ContentMX Privacy Policy: https://www.contentmx.com/privacy-policy/ Other policies: https://www.contentmx.com/legal/
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C