WP-Paginate

WP-Paginate has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2021 and 2022; all 2 are fixed as of September 2026. Their average CVSS score is 5.2, and the most serious one scores 5.5 out of 10.

The most common weakness is Cross-Site Scripting, behind 2 of the records (100%).

Every one of the 2 issues recorded for WP-Paginate has a vendor fix available, so running the current release closes all known holes.

2 independent researchers contributed these findings, one record each. WP-Paginate is installed on roughly 20,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSMedium
5.2/ 10
Patch Coverage100%
Open

0

Fixed

2

Get automatic notifications for all WP-Paginate vulnerabilities before they are exploited.

Highest severity on recordCVSS 5.5CVE-2022-2050

WP-Paginate <= 2.1.8 - Authenticated (Admin+) Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

2 records
WP-Paginate banner
Latestv2.2.6

WP-Paginate

maxfoundry

Author

maxfoundry

4.6(107)
92/100
Last Updated
2026-05-21 (4mo ago)
Active Installs
20,000+
Downloads
1,042,720
Requires WP
3.0+
Requires PHP
0+
Tested up to
WP 7.0.4
Created
2009-09-04 (17y ago)

Latest News WP-Paginate is a simple and flexible pagination plugin which provides users with better navigation on your WordPress site. In addition to increasing the user experience for your visitors, it has also been widely reported that pagination increases the SEO of your site by providing more links to your content. You can add custom CSS for your pagination links with the Custom CSS tab in WP-Paginate Settings. Starting in version 1.1, WP-Paginate can also be used to paginate post comments! Translations: https://plugins.svn.wordpress.org/wp-paginate/I18n (check the version number for the correct file)

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C