Series
Series has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Series has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by Muhammad Yudha - DJ. Series is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 5.0.27.
CVE-2025-62759Series <= 2.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Series
Author
Justin Tadlock
Series is a plugin created to allow users to easily link posts together by using a WordPress taxonomy (like tags or categories) called “series”. It can be particularly useful if you write several posts spanning the same topic and want them tied together in some way that tags or categories doesn’t cover. Professional Support If you need professional plugin support from me, the plugin author, you can access the support forums at Theme Hybrid, which is a professional WordPress help/support site where I handle support for all my plugins and themes for a community of 75,000+ users (and growing). Plugin Development If you’re a theme author, plugin author, or just a code hobbyist, you can follow the development of this plugin on it’s GitHub repository. Donations Yes, I do accept donations. If you want to donate, you can do so from my donations page or grab me something from my Amazon Wish List. I appreciate all donations, no matter the size. Further development of this plugin is not contingent on donations, but they are always a nice incentive.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C