WP People

WP People has one disclosed vulnerability in the WordSec catalog, all reported in 2008; it remains unpatched as of September 2026. Their average CVSS score is 9.8, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 0 high.

The most common weakness is SQL Injection, behind 1 of the records (100%).

The one issue recorded for WP People has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2008.

All of these findings were reported by S@BUN. The current release is tested up to WordPress 2.8.4.

Strategic Overview

Avg CVSSCritical
9.8/ 10
Patch Coverage0%
Open

1

Fixed

0

Get automatic notifications for all WP People vulnerabilities before they are exploited.

Most severe open issueCVSS 9.8CVE-2008-0845

WP People <= 3.4.1 - SQL Injection

Read the full analysis

Vulnerability Records

1 records
2008-02-18 00:00CVE-2008-0845
9.8
Critical
S@BUNNo
Showing 1–1 of 1 reports
Plugin Profile
Latestv3.4.1
0.0(0)
0/100
Last Updated
2009-08-13 (17y ago)
Active Installs
0+
Downloads
2,276
Requires WP
2.7.1+
Requires PHP
0+
Tested up to
WP 2.8.4
Created
2009-03-12 (18y ago)

This plug-in will search a post and find names that match database records of people maked with the WP People Category in the XFN Links. When it finds a match, it will replace the name with a link to the person. There is a administration screen for adding people and their bios to the database viewing the current people marked for the filter. More than one person can be linked on a post. A individual name will only be linked once per post. The original author of the hack stopped supporting it a while ago. I took his original idea and used another hack (acronymit) as a guide to make this work. The original worked with the my-hacks script used in WordPress 1.0.1, so this is beyond the functionality of the original. If you were using the version 2 of Word Press People, then you will be able to see any current people in WP People and COPY them to the XFN database.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C