Markup Markdown

Markup Markdown has 3 disclosed vulnerabilities in the WordSec catalog, all reported in 2025; all 3 are fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10. 2025 was the busiest year with 3 disclosures.

The most common weakness is Cross-Site Scripting, behind 3 of the records (100%).

Every one of the 3 issues recorded for Markup Markdown has a vendor fix available, so running the current release closes all known holes.

3 independent researchers contributed these findings, one record each. Markup Markdown is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSMedium
6.4/ 10
Patch Coverage100%
Open

0

Fixed

3

Get automatic notifications for all Markup Markdown vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.4CVE-2025-9540

Markup Markdown <= 3.20.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

3 records
Markup Markdown banner
Latestv4.0.2
5.0(11)
100/100
Last Updated
2026-09-08 (5d ago)
Active Installs
1,000+
Downloads
53,312
Requires WP
6.6+
Requires PHP
7.2.0+
Tested up to
WP 7.1
Created
2022-01-06 (5y ago)

This plugin replaces the Gutenberg block editor (or the classic TinyMCE) on the edit screen with EasyMDE, a markdown editor based on CodeMirror, fine-tuned to work smoothly with the WordPress admin panels. The content is saved with the markdown syntax in the database and is rendered on the frontend thanks to the Parsedown PHP library after being sanitized via WordPress native filters. That’s pretty all you should know. It’s under active development, keep in touch and feel free to drop a line on the forum, to let a rating or even support me by buying a coffee !

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C