Simple Spoiler
Simple Spoiler has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2025; all 3 are fixed as of September 2026. Their average CVSS score is 6.0, and the most serious one scores 7.3 out of 10. Severity breakdown: 0 critical and 1 high. 2024 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Scripting, behind 2 of the records (67%). Other recurring categories include Code Injection.
Every one of the 3 issues recorded for Simple Spoiler has a vendor fix available, so running the current release closes all known holes.
3 independent researchers contributed these findings, one record each. Simple Spoiler is installed on roughly 2,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
CVE-2024-8479Simple Spoiler 1.2 - 1.3 - Unauthenticated Arbitrary Shortcode Execution
Read the full analysisVulnerability Records

Simple Spoiler
Author
Webliberty
Use spoilers to hide some content on the page using shortcode. On the settings page, you can specify the color of the spoiler. How to use Example: [spoiler]Spoiler content[/spoiler] Example: [spoiler title="Show spoiler"]Spoiler content[/spoiler] Translations You can translate Simple Spoiler on translate.wordpress.org.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C