Timeline Pro
Timeline Pro has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Timeline Pro has a vendor fix available, so running the current release closes it.
All of these findings were reported by SOPROBRO. Timeline Pro is installed on roughly 50 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.7.7.
CVE-2025-22584Timeline Pro <= 1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via [placeholder]
Read the full analysisVulnerability Records

Timeline Pro
Author
PluginsPoint
Timeline Pro is pure HTML & CSS timeline style grid for WordPress. Very lightweight, Responsive and easy to use anywhere via short-codes, control timeline multiple post type via admin settings panel. use your color to match theme. Social share icon to share timeline post to most popular social network site. beautiful ajax load more timeline post and comments. Live Preview Support Plugin Features Use via shortcode. Display any post type. Select Multiple Categories. Select Post by Title. Custom color. Title color Options Ajax load more post. Load More Font Size. Load More Color. Ajax Comments Color. Ajax Comments Font Size. Featured post marker. Social Share button. Click to zoom view for readers. Support any themes
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C