WP People
WP People has one disclosed vulnerability in the WordSec catalog, all reported in 2008; it remains unpatched as of September 2026. Their average CVSS score is 9.8, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 0 high.
The most common weakness is SQL Injection, behind 1 of the records (100%).
The one issue recorded for WP People has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2008.
All of these findings were reported by S@BUN. The current release is tested up to WordPress 2.8.4.
CVE-2008-0845WP People <= 3.4.1 - SQL Injection
Read the full analysisVulnerability Records
WP People
Author
LoganSix
This plug-in will search a post and find names that match database records of people maked with the WP People Category in the XFN Links. When it finds a match, it will replace the name with a link to the person. There is a administration screen for adding people and their bios to the database viewing the current people marked for the filter. More than one person can be linked on a post. A individual name will only be linked once per post. The original author of the hack stopped supporting it a while ago. I took his original idea and used another hack (acronymit) as a guide to make this work. The original worked with the my-hacks script used in WordPress 1.0.1, so this is beyond the functionality of the original. If you were using the version 2 of Word Press People, then you will be able to see any current people in WP People and COPY them to the XFN database.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C