WP Tesseract
WP Tesseract has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 4.4, and the most serious one scores 4.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for WP Tesseract has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by Nabil Irawan. WP Tesseract is installed on roughly 40 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 5.5.0.
CVE-2025-60176WP Tesseract <= 1.0.2 - Authenticated (Administrator+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

WP Tesseract
Author
tattersoftware
A plugin for extracting text from attached images using OCR via Tesseract. This plugin adds a new post named for each image upload containing any recognized text characters within the file. This text can then be edited for accuracy and used elsewhere on the site. The OCR plugin requires a supported version of PHP with the GD extension and the following command line utility: * Tesseract for the actual OCR This utility must be manually installed on your server and executable by PHP. This process, and consequently this plugin, is recommended only for advanced users.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C