CPO Content Types
CPO Content Types has one disclosed vulnerability in the WordSec catalog, all reported in 2023; it is fixed as of September 2026. Their average CVSS score is 4.4, and the most serious one scores 4.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for CPO Content Types has a vendor fix available, so running the current release closes it.
All of these findings were reported by Rio Darmawan. CPO Content Types is installed on roughly 3,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2023-25451CPO Content Types <= 1.1.0 - Authenticated (Administrator+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

CPO Content Types
Author
WP Chill
NOTE: This plugin is meant for use with the WordPress themes developed by CPOThemes themes, which take advantage of it to add richer content areas and designs. Check them out! CPO Content Types is a utility plugin that adds support for a specific set of content elements within your WordPress installation. This plugin will add seven custom post types to your site: slides, features, portfolios, services, team members, testimonials and clients. You can still use CPO Content Types for any WordPress theme, although you will have to create your own page templates. Included Content Types Slides Feature Blocks Portfolio Items Services Team Members Testimonials Clients Highlights Only the content types supported by the current WordPress theme will be shown, to avoid crowding your admin menu. You can still override this and show any content types if you want. This plugin is perfectly compatible with any theme: you will be able to manage your content just fine. However, there are no templates included and it is up to the theme to handle them. The portfolio post type included here is different from other portfolio plugins, and can be used in conjunction with them. For instance, you can still use JetPack portfolios at the same time.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C