Zotpress

Zotpress has 8 disclosed vulnerabilities in the WordSec catalog, reported between 2016 and 2025; all 8 are fixed as of September 2026. Their average CVSS score is 6.8, and the most serious one scores 9.9 out of 10. Severity breakdown: 2 critical and 0 high. 2024 was the busiest year with 4 disclosures.

The most common weakness is Cross-Site Scripting, behind 5 of the records (63%). Other recurring categories include SQL Injection, Improper Access Control.

Every one of the 8 issues recorded for Zotpress has a vendor fix available, so running the current release closes all known holes.

7 independent researchers contributed these findings, most of them (2) reported by LVT-tholv2k. Zotpress is installed on roughly 2,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSMedium
6.8/ 10
Patch Coverage100%
Open

0

Fixed

8

Get automatic notifications for all Zotpress vulnerabilities before they are exploited.

Highest severity on recordCVSS 9.9CVE-2024-30488

Zotpress <= 7.3.7 - Authenticated (Contributor+) SQL Injection

Read the full analysis

Vulnerability Records

8 records
Zotpress banner
Latestv7.4.4

Zotpress

Katie

Author

Katie

4.9(66)
98/100
Last Updated
2026-08-08 (1mo ago)
Active Installs
2,000+
Downloads
139,608
Requires WP
3.6+
Requires PHP
0+
Tested up to
WP 7.0.4
Created
2011-02-05 (16y ago)

Zotpress brings publication broadcasting and scholarly blogging to WordPress through Zotero, a free, cross-platform reference manager. Features Displays your personal and group Zotero items through in-text citations, bibliographies, and searchable libraries Supports thumbnail images through WordPress’s Media Library and Open Library Supports selective CSS styling via IDs and classes Provides a range of additional features, such as allowing visitors to download citations And more! Compatible with Firefox, Safari, Chrome, and IE9. Made with jQuery, jQuery UI, jQuery doTimeout, Live Query, OAuth, and Open Library. Special thanks to Joe Alberts for substantial contributions to the code, comprehensive testing, and design ideation. Thanks also to contributors Jeremy Varnham (@jvarn13), Christopher Cheung, Jason S., Chris Wentzloff, Karljürgen Feuerherm (@feuerherm), Mark Dingemanse (@codeispoetry), Jörg Mechnich (jmechnich@github), Tomas Risberg, @ericcorbett2, @timtom, @alhrath, and André Lambelet for their code contributions, testing, and guidance. Finally, my sincere gratitude goes out to all who have donated in support of this plugin. Please note that this plugin is on semi-hiatus, with updates expected about 1-3 times a year. Requirements jQuery included in your theme (Zotpress will do this for you if it isn’t already included), and an HTTP request method supported by WordPress enabled on your server: cURL, fopen with Streams (PHP 5), or fsockopen. In your server config file, X-Frame-Options should be set to SAMEORIGIN. Optional: OAuth enabled on your server.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C