My Favorites
My Favorites has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2024; all 2 are fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10. 2024 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Scripting, behind 2 of the records (100%).
Every one of the 2 issues recorded for My Favorites has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. My Favorites is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2024-49263My Favorites <= 1.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

My Favorites
Author
Takashi Matsuyama
Save user’s favorite posts and list them. This plugin is simple. You can save the user’s favorite posts just a install and display them anywhere you want with just a shortcode. The logged-in user’s data is saved in the user meta. Other user’s data is saved to Web Storage (localStorage). Usage Shortcode: [ccc_my_favorite_select_button post_id="" style=""] Shortcode: [ccc_my_favorite_list_menu slug="" text="" style=""] Shortcode: [ccc_my_favorite_list_results class="" style=""] For pages with a shortcode for list view ([ccc_my_favorite_list_results]). “Load More” is displayed with “posts_per_page”. It will be displayed when the user has more favorite posts than “posts_per_page”. Shortcode: [ccc_my_favorite_list_results posts_per_page="10"] default is 100 posts. You can display the post’s “excerpt”. This value is the char length. If not needed, use “no excerpt” or “0”. Shortcode: [ccc_my_favorite_list_results excerpt="30"] If you want, you can change the code for list view yourself. Shortcode: [ccc_my_favorite_list_custom_template style=""] For pages with a shortcode for custom list view ([ccc_my_favorite_list_custom_template]). Add the function (function ccc_my_favorite_list_custom_template( $my_favorite_post_id ) { }) for your list view to your-theme/functions.php. $my_favorite_post_id is array. style=”none” excludes the default CSS for the list. Detailed usage is under preparation. Discover More This plugin is developed on GitHub
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C