Simple Presenter
Simple Presenter has one disclosed vulnerability in the WordSec catalog, all reported in 2024; it is fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Simple Presenter has a vendor fix available, so running the current release closes it.
All of these findings were reported by João Pedro Soares de Alcântara. Simple Presenter is installed on roughly 10 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.6.7.
CVE-2024-54340Simple Presenter <= 1.5.1 - Reflected Cross-Site Scripting
Read the full analysisVulnerability Records
Simple Presenter
Author
sylviavanos
Simple Presenter was born out of a request within one of the companies I was assigned to to replace the current digital signage solution. Due to the fact that WordPress was used by everyone who had to manage it, and the lack of finding any solution that really worked for us without a huge investment of time, it was decided to code up our own WordPress plugin. This is that plugin. Simple Presenter allows you to: – Define an infinite number of screens – Set a logo image, background color and text color for each screen – Show events from an infinite number of calendars (only Tribe via the JSON API is currently supported, max 5 events per calendar are shown) – An infinite number of extra slides of practically any content (image, html, shortcodes, embeds, etc.) – Choose exactly what to display on which screen – Control who can manage Simple Presenter using the manage_simplepresenter capability (may require third-party plugins) Simple Presenter is meant to be simple above powerful and is written for the purposes of a single company. However, it was decided the plugin is useful and generic enough to publish it for broader use.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C