Secondary Title
Secondary Title has one disclosed vulnerability in the WordSec catalog, all reported in 2023; it is fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Secondary Title has a vendor fix available, so running the current release closes it.
All of these findings were reported by TaeEun Lee. Secondary Title is installed on roughly 7,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2023-28773Secondary Title <= 2.0.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Secondary Title
Author
thaikolja
Secondary Title is a simple, light-weight plugin that adds an alternative title to posts, pages, and/or custom post types, which can be displayed automatically, with a shortcode or by using PHP. The plugin comes with an extra settings page, which allows you to customize the plugin according to your needs. You can change: post types, categories, and specific post IDs the secondary title will be shown on, whether the secondary title should be automatically added to the standard title (Auto show), the format both titles are being shown (only works when Auto show is activated), the position where the secondary title input field should be displayed (above or below the standard title) within the admin interface (Classic Editor only), whether the secondary title should only be displayed in the main post and not within widgets, etc., if the secondary title should be usable in permalinks, and even more. Please see the official website for a full documentation.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C