WP Super Edit
WP Super Edit has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2025 and 2026; none of them are fixed as of September 2026. Their average CVSS score is 7.5, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 1 high.
The most common weakness is Cross-Site Scripting, behind 1 of the records (50%). Other recurring categories include Unrestricted Upload Of File With Dangerous Type.
None of the 2 issues recorded for WP Super Edit have a published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
2 independent researchers contributed these findings, one record each. WP Super Edit is installed on roughly 2,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 5.4.0.
CVE-2021-47965WP Super Edit <= 2.5.4 - Unauthenticated Arbitrary File Upload
Read the full analysisVulnerability Records
WP Super Edit
Author
Ahmad Awais
Major Update Due Soon! This plugin is getting a major update soon. WP Super Edit is designed to get control of the WordPress wysiwyg visual editor and add some functionality with more buttons and customized TinyMCE plugins. WP Super edit acts as framework for TinyMCE visual editor plugins and buttons allowing administrators (or users) to arrange buttons and add TinyMCE plugins to the visual editor. Your feedback is always welcome! Features Drag and Drop interface for arranging the WordPress visual editor buttons. Access to built-in WordPress visual editor buttons and functions. Additional TinyMCE plugins to add buttons and features like tables, layers (div tag), advanced XHTML properties, advanced image and link properties, WordPress emoticons, style attributes, css classes for themes, search / replace, and more. Options for allowing users to configure visual editor settings; One editor setting for all users, role based editor settings, and individual user editor settings. Only WordPress administrators can activate or deactivate TinyMCE wysiwyg visual editor plugins. In single or role based modes, only administrators can arrange editor buttons. Easy to install and remove. WP Super Edit uses separate database tables for settings and to support multi-site configurations. Currently only the Super Emoticon / Icon Plugin will leave short tags in your posts or pages. Version Notice This version has been tested for use with the versions of WordPress indicated. I attempt to keep WP Super Edit up to date with changes to WordPress and the visual editor, but the complex changes can make it unproductive to maintain compatiblity with some older versions of WordPress. This is a list of recent versions available for older WordPress sites. Use WP Super Edit 2.1 for WordPress 2.6 to 2.7.1 Use WP Super Edit 2.3.x for WordPress 2.8 to 3.1.x Use WP Super Edit 2.4.x for WordPress 3.1 to 3.8.x Download Older Versions of WP Super Edit
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C