WP Custom Author URL

WP Custom Author URL has one disclosed vulnerability in the WordSec catalog, all reported in 2023; it is fixed as of September 2026. Their average CVSS score is 4.4, and the most serious one scores 4.4 out of 10.

The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).

The one issue recorded for WP Custom Author URL has a vendor fix available, so running the current release closes it.

All of these findings were reported by Shreya Pohekar. WP Custom Author URL is installed on roughly 5,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.

Strategic Overview

Avg CVSSMedium
4.4/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all WP Custom Author URL vulnerabilities before they are exploited.

Highest severity on recordCVSS 4.4CVE-2023-1614

WP Custom Author URL <= 1.0.4 - Authenticated (Administrator+) Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

1 records
WP Custom Author URL banner
Latestv2.1.0

WP Custom Author URL

Poodle Plugins

Author

Poodle Plugins

5.0(8)
100/100
Last Updated
2026-04-07 (5mo ago)
Active Installs
5,000+
Downloads
29,115
Requires WP
3.0.1+
Requires PHP
5.6+
Tested up to
WP 6.9.7
Created
2019-05-03 (8y ago)

This plugin will allow you to choose a custom URL for your author links, instead of the standard WordPress author page. This can be useful if you want to link to your own Twitter, LinkedIn or other social media profile. There are two areas where this plugin can be configured: Firstly, a global settings section is available under WordPress Settings. Second, under each users profile page. A user can set their own custom URL on their profile page, and this will apply just to them. This can can be overriden by the global admin setting, if the &#8216;Override Individual Authors’ setting is checked. Custom author URL’s also redirect author pages when directly accessed. For example if your user is called Bob, and you try to access https://yourblog.com/author/bob, it will redirect.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C