WP Custom Author URL
WP Custom Author URL has one disclosed vulnerability in the WordSec catalog, all reported in 2023; it is fixed as of September 2026. Their average CVSS score is 4.4, and the most serious one scores 4.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for WP Custom Author URL has a vendor fix available, so running the current release closes it.
All of these findings were reported by Shreya Pohekar. WP Custom Author URL is installed on roughly 5,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2023-1614WP Custom Author URL <= 1.0.4 - Authenticated (Administrator+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

WP Custom Author URL
Author
Poodle Plugins
This plugin will allow you to choose a custom URL for your author links, instead of the standard WordPress author page. This can be useful if you want to link to your own Twitter, LinkedIn or other social media profile. There are two areas where this plugin can be configured: Firstly, a global settings section is available under WordPress Settings. Second, under each users profile page. A user can set their own custom URL on their profile page, and this will apply just to them. This can can be overriden by the global admin setting, if the ‘Override Individual Authors’ setting is checked. Custom author URL’s also redirect author pages when directly accessed. For example if your user is called Bob, and you try to access https://yourblog.com/author/bob, it will redirect.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C