Simple Archive Generator
Simple Archive Generator has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2025 and 2026; none of them are fixed as of September 2026. Their average CVSS score is 5.2, and the most serious one scores 6.1 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (50%). Other recurring categories include Cross-Site Scripting.
None of the 2 issues recorded for Simple Archive Generator have a published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
2 independent researchers contributed these findings, one record each. Simple Archive Generator is installed on roughly 40 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 2.8.
CVE-2025-68880Simple Archive Generator <= 5.2 - Reflected Cross-Site Scripting
Read the full analysisVulnerability Records
Simple Archive Generator
Author
peterwsterling
A very simple (to use and configure), yet powerful, plug-in to generate a list (by category) of all posts. It’s simple because there is no fancy formatting, complex configuration or other ‘noise’, just a sensible archive list of all your posts! All that’s required is to include this <!-- simple_archive --> on a page (or post). How simple is that? Posts can be listed under every category, or just the first category they are filed under. Categories can be hierarchically listed. Categories can be sorted alphabetically or by creation order, while posts are listed chronologically. A comment count for each post can be displayed. Also, some simple statistics may also be shown. Internationalisation The Simple Archive generator provides support for language translation. Ensure WPLANG is set in your wp-config file. Then use the simple-archive.pot template to create a .po translation for your language, this then needs compiling to create a .mo file. For example, a German translation (simple-archive-de.po) is provided thanks to Ingo Terpelle at http://www.xing.com/profile/Ingo_Terpelle
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C