Crossword Compiler Puzzles

Crossword Compiler Puzzles has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2025; all 2 are fixed as of September 2026. Their average CVSS score is 7.6, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 1 high. 2025 was the busiest year with 2 disclosures.

The most common weakness is Cross-Site Scripting, behind 1 of the records (50%). Other recurring categories include Unrestricted Upload Of File With Dangerous Type.

Every one of the 2 issues recorded for Crossword Compiler Puzzles has a vendor fix available, so running the current release closes all known holes.

2 independent researchers contributed these findings, one record each. Crossword Compiler Puzzles is installed on roughly 200 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSHigh
7.6/ 10
Patch Coverage100%
Open

0

Fixed

2

Get automatic notifications for all Crossword Compiler Puzzles vulnerabilities before they are exploited.

Highest severity on recordCVSS 8.8CVE-2025-46490

Crossword Compiler Puzzles <= 5.2 - Authenticated (Subscriber+) Arbitrary File Upload

Read the full analysis

Vulnerability Records

2 records
Plugin Profile
Latestv14.7

Crossword Compiler Puzzles

wordwebsoftware

Author

wordwebsoftware

2.8(5)
56/100
Last Updated
2026-06-15 (3mo ago)
Active Installs
200+
Downloads
16,207
Requires WP
6.3+
Requires PHP
0+
Tested up to
WP 7.0.4
Created
2013-12-17 (13y ago)

Simple upload of interactive puzzles exported by Crossword Compiler, or conversion of puzzles already posted to the https://crossword.info website.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C