Markup Markdown
Markup Markdown has 3 disclosed vulnerabilities in the WordSec catalog, all reported in 2025; all 3 are fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10. 2025 was the busiest year with 3 disclosures.
The most common weakness is Cross-Site Scripting, behind 3 of the records (100%).
Every one of the 3 issues recorded for Markup Markdown has a vendor fix available, so running the current release closes all known holes.
3 independent researchers contributed these findings, one record each. Markup Markdown is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2025-9540Markup Markdown <= 3.20.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Markup Markdown
Author
Pierre-Henri Lavigne
This plugin replaces the Gutenberg block editor (or the classic TinyMCE) on the edit screen with EasyMDE, a markdown editor based on CodeMirror, fine-tuned to work smoothly with the WordPress admin panels. The content is saved with the markdown syntax in the database and is rendered on the frontend thanks to the Parsedown PHP library after being sanitized via WordPress native filters. That’s pretty all you should know. It’s under active development, keep in touch and feel free to drop a line on the forum, to let a rating or even support me by buying a coffee !
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C