CVE-2023-32116: Totalpress Custom Post Types

Medium severity, CVSS 4.8. EPSS: 0.3% chance of exploitation in the next 30 days.

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in TotalPress.Org Custom post types, Custom Fields & more plugin <= 4.0.12 versions.

Affected products

  • Totalpress Custom Post Types: up to and including 4.0.12

Published 2023-10-26. Last modified 2026-06-17.