Proofreading
Proofreading has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2025; all 2 are fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.
The most common weakness is Cross-Site Scripting, behind 2 of the records (100%).
Every one of the 2 issues recorded for Proofreading has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. Proofreading is installed on roughly 5,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.7.7.
CVE-2024-12466Proofreading <= 1.2.1.1 - Reflected Cross-Site Scripting
Read the full analysisVulnerability Records

Proofreading
Author
Scribit
Proofreading plugin allows you to improve the quality of your posts, pages and all your WordPress website. It gives you the possibility to check the correction of the texts inserted into posts, pages and drafts in less than a second! Press the “Analyze” button and you will have a list of all found errors. The plugin allows to recognize different types of text errors (thanks to Languagetool.org). Here some examples of error types: * Typos * Punctuation * Typography * Commonly Confused Words * Nonstandard phrases * Semantic * Grammar * Redundant Phrases Proofreading plugin supports a lot of languages. For example: * English * Spanish * German * Italian * Japanese * French * Portuguese * Russian * and so on… For every language, in the settings page, you can customize which are the error categories you are interesting, hiding the others.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C