Crossword Compiler Puzzles
Crossword Compiler Puzzles has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2025; all 2 are fixed as of September 2026. Their average CVSS score is 7.6, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 1 high. 2025 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Scripting, behind 1 of the records (50%). Other recurring categories include Unrestricted Upload Of File With Dangerous Type.
Every one of the 2 issues recorded for Crossword Compiler Puzzles has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. Crossword Compiler Puzzles is installed on roughly 200 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2025-46490Crossword Compiler Puzzles <= 5.2 - Authenticated (Subscriber+) Arbitrary File Upload
Read the full analysisVulnerability Records
Crossword Compiler Puzzles
Author
wordwebsoftware
Simple upload of interactive puzzles exported by Crossword Compiler, or conversion of puzzles already posted to the https://crossword.info website.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C