WP-ShowHide
WP-ShowHide has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2025; all 2 are fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 2 of the records (100%).
Every one of the 2 issues recorded for WP-ShowHide has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. WP-ShowHide is installed on roughly 9,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2025-67541WP-ShowHide <= 1.05 - Authenticated (Contributor+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

WP-ShowHide
Author
Lester Chan
WP-ShowHide hides part of a post behind a button, so something long — a press release, a changelog, a spoiler — does not fill the page until a reader asks for it. The button says how many words it is hiding, which is what Engadget does with their press releases. Example usage: [showhide type="pressrelease"]Press Release goes in here.[/showhide] There is nothing to configure and no settings screen. Every choice the plugin offers is an attribute of the shortcode that makes it, so two toggles in the same post can behave differently. Features One shortcode, [showhide], usable any number of times in a post or page A Show/Hide block for the block editor, holding the content it hides as ordinary blocks and rendering exactly what the shortcode renders A button rather than a link, with aria-expanded and aria-controls, so the toggle works from the keyboard and reads correctly to a screen reader Labels that count the words they are hiding No jQuery, and no script at all on a page that uses neither the shortcode nor the block Custom DOM events on every toggle, for themes that want to react to one Donations I spent most of my free time creating, updating, maintaining and supporting these plugins, if you really love my plugins and could spare me a couple of bucks, I will really appreciate it. If not feel free to use it without any obligations. Usage By default, content within the showhide shortcode will be hidden. Example: [showhide]Press release content goes in here.[/showhide] Default Values: [showhide type="pressrelease" more_text="Show Press Release (%s More Words)" less_text="Hide Press Release (%s Less Words)" hidden="yes"] You can have multiple showhide content within a post or a page, just by having a new type. Example: [showhide type="links" more_text="Show Links (%s More Words)" less_text="Hide Links (%s Less Words)"]Links will go in here.[/showhide] If you want to set the default visibility to display. Example: [showhide hidden="no"]Press release content goes in here.[/showhide] Block editor There is a Show/Hide block too, filed under Text in the inserter. It holds the content it hides as ordinary blocks — paragraphs, images, anything — so that content is written and edited in place instead of being typed into a field as markup, and it stays visible while you are editing. The Show/Hide panel in the sidebar carries the same four choices the shortcode attributes carry: the type, the two button labels, and whether it starts hidden. The shortcode is unchanged and still supported. It is not deprecated, posts that use it need no editing, the block and the shortcode render the same markup, and one post can hold both. You can style the content via CSS that is generated by the plugin. Here is a sample of the generated HTML. Note that pressrelease is the default type. <div id="pressrelease-link-1" class="wp-showhide sh-link pressrelease-link sh-hide"> <button type="button" class="sh-toggle" aria-expanded="false" aria-controls="pressrelease-content-1" data-sh-more="Show Press Release (4 More Words)" data-sh-less="Hide Press Release (4 Less Words)">Show Press Release (4 More Words)</button> </div> <div id="pressrelease-content-1" class="wp-showhide sh-content pressrelease-content sh-hide" hidden>Content</div> With the example above, here are the following styles you can use in your CSS: .sh-link { } .sh-toggle { } .sh-content { } .pressrelease-link { } .pressrelease-link.sh-hide .sh-toggle { } .pressrelease-link.sh-show .sh-toggle { } .pressrelease-content { } .pressrelease-content.sh-hide { } .pressrelease-content.sh-show { } Every toggle fires three events on the .sh-link element, and all three bubble, so one listener on the document covers every toggle on the page: sh-link:more when a toggle opens, sh-link:less when it closes, and sh-link:toggle on both.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C