Modern Footnotes
Modern Footnotes has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2025; all 3 are fixed as of September 2026. Their average CVSS score is 5.7, and the most serious one scores 6.4 out of 10. 2023 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Scripting, behind 3 of the records (100%).
Every one of the 3 issues recorded for Modern Footnotes has a vendor fix available, so running the current release closes all known holes.
3 independent researchers contributed these findings, one record each. Modern Footnotes is installed on roughly 6,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2025-50049Modern Footnotes <= 1.4.19 - Authenticated (Contributor+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Modern Footnotes
Author
prismtechstudios
Footnotes optimized for desktop and mobile, inspired by the styles of Grantland and FiveThirtyEight. Use a footnote in your post by using the footnote icon in the WordPress editor or by using the shortcode: [mfn]this will be a footnote[/mfn] The plugin will automatically associate sequential numbers with each plugin. On desktop, footnotes will appear as a tooltip when the user clicks on the number. On mobile, footnotes will expand as a section below the current text. You can also use the [mfn_list] shortcode to display a list of footnotes used in the article. The official GitHub repository is at https://github.com/seankwilliams/modern-footnotes Shortcode options You can modify some behaviours or styles of your footnotes by using the following options within our shortcode. [mfn referencenumber=3]This footnote will have the number 3[/mfn] [mfn class=’my-pretty-class’]This footnote will have ‘my-pretty-class’ as additional class, allowing for custom styling of individual footnotes.[/mfn] [mfn referencereset=’true’]This footnote will reset the footnote counter and therfore receive 1 as its number. Following footnotes will also receive their number according to this new start.[/mfn]
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C