Simple Staff List
Simple Staff List has 3 disclosed vulnerabilities in the WordSec catalog, all reported in 2023; all 3 are fixed as of September 2026. Their average CVSS score is 5.4, and the most serious one scores 6.4 out of 10. 2023 was the busiest year with 3 disclosures.
The most common weakness is Cross-Site Scripting, behind 2 of the records (67%). Other recurring categories include Missing Authorization.
Every one of the 3 issues recorded for Simple Staff List has a vendor fix available, so running the current release closes all known holes.
3 independent researchers contributed these findings, one record each. Simple Staff List is installed on roughly 3,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.0.
CVE-2023-23686Simple Staff List <= 2.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Read the full analysisVulnerability Records

Simple Staff List
Author
Brett Shumaker
The Simple Staff List plugin allows you to build a staff directory for your website. You get an easy-to-use interface which allows you to edit the following fields for each staff member: Name, Photo, Position, Email, Phone Number, and Bio. There’s also a drag-and-drop interface to set the order of your staff members. You’ll use the [simple-staff-list] shortcode within a page or post to display the full staff listing in the order set on the “Order” page. You’ll be able to customize the information shown for each staff member on your website by editing a simple template. You can add your own custom CSS to style your staff list as well. Use the Simple Staff List support section to post any problems/comments!
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C