My Favorites

My Favorites has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2024; all 2 are fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10. 2024 was the busiest year with 2 disclosures.

The most common weakness is Cross-Site Scripting, behind 2 of the records (100%).

Every one of the 2 issues recorded for My Favorites has a vendor fix available, so running the current release closes all known holes.

2 independent researchers contributed these findings, one record each. My Favorites is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.

Strategic Overview

Avg CVSSMedium
6.4/ 10
Patch Coverage100%
Open

0

Fixed

2

Get automatic notifications for all My Favorites vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.4CVE-2024-49263

My Favorites <= 1.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

2 records
My Favorites banner
Latestv1.4.4
5.0(15)
100/100
Last Updated
2026-01-09 (8mo ago)
Active Installs
1,000+
Downloads
20,041
Requires WP
4.8+
Requires PHP
5.4.0+
Tested up to
WP 6.9.7
Created
2021-01-20 (6y ago)

Save user’s favorite posts and list them. This plugin is simple. You can save the user’s favorite posts just a install and display them anywhere you want with just a shortcode. The logged-in user’s data is saved in the user meta. Other user’s data is saved to Web Storage (localStorage). Usage Shortcode: [ccc_my_favorite_select_button post_id="" style=""] Shortcode: [ccc_my_favorite_list_menu slug="" text="" style=""] Shortcode: [ccc_my_favorite_list_results class="" style=""] For pages with a shortcode for list view ([ccc_my_favorite_list_results]). “Load More” is displayed with “posts_per_page”. It will be displayed when the user has more favorite posts than “posts_per_page”. Shortcode: [ccc_my_favorite_list_results posts_per_page="10"] default is 100 posts. You can display the post’s “excerpt”. This value is the char length. If not needed, use “no excerpt” or “0”. Shortcode: [ccc_my_favorite_list_results excerpt="30"] If you want, you can change the code for list view yourself. Shortcode: [ccc_my_favorite_list_custom_template style=""] For pages with a shortcode for custom list view ([ccc_my_favorite_list_custom_template]). Add the function (function ccc_my_favorite_list_custom_template( $my_favorite_post_id ) { }) for your list view to your-theme/functions.php. $my_favorite_post_id is array. style=”none” excludes the default CSS for the list. Detailed usage is under preparation. Discover More This plugin is developed on GitHub

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C