Proofreading

Proofreading has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2025; all 2 are fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.

The most common weakness is Cross-Site Scripting, behind 2 of the records (100%).

Every one of the 2 issues recorded for Proofreading has a vendor fix available, so running the current release closes all known holes.

2 independent researchers contributed these findings, one record each. Proofreading is installed on roughly 5,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.7.7.

Strategic Overview

Avg CVSSMedium
6.1/ 10
Patch Coverage100%
Open

0

Fixed

2

Get automatic notifications for all Proofreading vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.1CVE-2024-12466

Proofreading <= 1.2.1.1 - Reflected Cross-Site Scripting

Read the full analysis

Vulnerability Records

2 records
Proofreading banner
Latestv1.2.2

Proofreading

Scribit

Author

Scribit

4.0(8)
80/100
Last Updated
2025-01-16 (2y ago)
Active Installs
5,000+
Downloads
13,274
Requires WP
4.0+
Requires PHP
5.6+
Tested up to
WP 6.7.7
Created
2018-02-23 (9y ago)

Proofreading plugin allows you to improve the quality of your posts, pages and all your WordPress website. It gives you the possibility to check the correction of the texts inserted into posts, pages and drafts in less than a second! Press the “Analyze” button and you will have a list of all found errors. The plugin allows to recognize different types of text errors (thanks to Languagetool.org). Here some examples of error types: * Typos * Punctuation * Typography * Commonly Confused Words * Nonstandard phrases * Semantic * Grammar * Redundant Phrases Proofreading plugin supports a lot of languages. For example: * English * Spanish * German * Italian * Japanese * French * Portuguese * Russian * and so on… For every language, in the settings page, you can customize which are the error categories you are interesting, hiding the others.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C