Novelist
Novelist has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2025; all 3 are fixed as of September 2026. Their average CVSS score is 4.4, and the most serious one scores 4.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 2 of the records (67%). Other recurring categories include Cross-Site Request Forgery (CSRF).
Every one of the 3 issues recorded for Novelist has a vendor fix available, so running the current release closes all known holes.
3 independent researchers contributed these findings, one record each. Novelist is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2025-30847Novelist <= 1.2.3 - Authenticated (Administrator+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Novelist
Author
Ashley
Novelist helps authors easily organize and display their portfolio of books. Features: All books are stored in their own “Books” area. Easy form for filling out book information. All book information is automatically formatted for you. Customizable templates. Easily create an archive of all your books. Developer-friendly. Available Book Info Fields: Title Book Cover Series (name and number) Contributors Publisher Release Date Genres Pages Synopsis Goodreads Link Purchase Links (configure your own list of retail sites) ISBN13 ASIN Excerpt Extra Text Documentation Extensive documentation is available at novelistplugin.com/docs
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C