EasyIndex
EasyIndex has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for EasyIndex has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by Nabil Irawan. EasyIndex is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 5.3.23.
CVE-2025-62117EasyIndex <= 1.1.1704 - Cross-Site Request Forgery
Read the full analysisVulnerability Records

EasyIndex
Author
Jayce53
It’s EASY to create an index on your WordPress blog with EasyIndex. It works right out of the box. Most other index solutions require you to laboriously select and add each category or tag you want to index , or even look up category and post IDs. With EasyIndex, you just select the things you want to index from a list and the plugin can create an index almost instantly. With other index solutions, you are stuck with just one format – EasyIndex has 9 index styles (26 in the Plus version) that you can easily customize with different fonts, colors, text styles and HTML tags. You can easily add indexes to your menu, and if you want, EasyIndex will automatically make submenu items as required. And according to our Beta Testers, the link to a relevant help page that’s next to every field on the setup screen really made using EasyIndex a breeze. As well as generating indexes, EasyIndex Plus creates customizable sidebar photo galleries – which you can also embed in posts using a shortcode. Want a gallery of your latest posts but only include posts from selected categories? EasyIndex Plus can do that with just a few clicks. Would you like to make a Pinterest style gallery from your posts? If you’ve got EasyIndex Plus and a spare 30 seconds, you’re done!
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C