Zotpress
Zotpress has 8 disclosed vulnerabilities in the WordSec catalog, reported between 2016 and 2025; all 8 are fixed as of September 2026. Their average CVSS score is 6.8, and the most serious one scores 9.9 out of 10. Severity breakdown: 2 critical and 0 high. 2024 was the busiest year with 4 disclosures.
The most common weakness is Cross-Site Scripting, behind 5 of the records (63%). Other recurring categories include SQL Injection, Improper Access Control.
Every one of the 8 issues recorded for Zotpress has a vendor fix available, so running the current release closes all known holes.
7 independent researchers contributed these findings, most of them (2) reported by LVT-tholv2k. Zotpress is installed on roughly 2,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2024-30488Zotpress <= 7.3.7 - Authenticated (Contributor+) SQL Injection
Read the full analysisVulnerability Records

Zotpress
Author
Katie
Zotpress brings publication broadcasting and scholarly blogging to WordPress through Zotero, a free, cross-platform reference manager. Features Displays your personal and group Zotero items through in-text citations, bibliographies, and searchable libraries Supports thumbnail images through WordPress’s Media Library and Open Library Supports selective CSS styling via IDs and classes Provides a range of additional features, such as allowing visitors to download citations And more! Compatible with Firefox, Safari, Chrome, and IE9. Made with jQuery, jQuery UI, jQuery doTimeout, Live Query, OAuth, and Open Library. Special thanks to Joe Alberts for substantial contributions to the code, comprehensive testing, and design ideation. Thanks also to contributors Jeremy Varnham (@jvarn13), Christopher Cheung, Jason S., Chris Wentzloff, Karljürgen Feuerherm (@feuerherm), Mark Dingemanse (@codeispoetry), Jörg Mechnich (jmechnich@github), Tomas Risberg, @ericcorbett2, @timtom, @alhrath, and André Lambelet for their code contributions, testing, and guidance. Finally, my sincere gratitude goes out to all who have donated in support of this plugin. Please note that this plugin is on semi-hiatus, with updates expected about 1-3 times a year. Requirements jQuery included in your theme (Zotpress will do this for you if it isn’t already included), and an HTTP request method supported by WordPress enabled on your server: cURL, fopen with Streams (PHP 5), or fsockopen. In your server config file, X-Frame-Options should be set to SAMEORIGIN. Optional: OAuth enabled on your server.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C