PLUGIN SECURITY
Is Cornerstone safe?
Enhanced content management for WordPress
What this plugin does
- Slug:
cornerstone - Author: Archetyped
- 30000+ active installs
- 80/100 rating (6 reviews on wordpress.org)
- 70423 all-time downloads
- On WordPress.org since 2010-12-30
cmsmanagementorganizationsectionsstructure
Maintenance status
- Latest known version: 0.8.1
- Last updated: 2026-07-21 10:28pm GMT
- Tested up to WordPress: 7.0.4
- Max supported PHP (analyzed): <8.0
Known vulnerabilities
7 known CVEs on file for Cornerstone. Reported between 2024 and 2026.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-9710 | Cornerstone [cornerstone] < 7.8.8 (closed) | Exposure of Sensitive Information to an Unauthorized Actor | Unknown | < 7.8.8 | 7.8.8 | 2026-06-24 | ⚠ update needed |
| CVE-2026-9709 | Cornerstone [cornerstone] < 7.8.9 (closed) | Exposure of Sensitive Information to an Unauthorized Actor | Unknown | < 7.8.9 | 7.8.9 | 2026-06-24 | ⚠ update needed |
| CVE-2026-54185 | Cornerstone [cornerstone] < 7.8.8 (closed) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | High 8.5 | < 7.8.8 | 7.8.8 | 2026-06-16 | ⚠ update needed |
| CVE-2026-49113 | Cornerstone [cornerstone] < 7.8.8 (closed) | Improper Control of Generation of Code ('Code Injection') | High 8.5 | < 7.8.8 | 7.8.8 | 2026-06-04 | ⚠ update needed |
| CVE-2025-63072 | Cornerstone [cornerstone] <= 7.7.3 (unfixed + closed) | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 7.7.3 | 7.7.3 | 2025-10-06 | ⚠ update needed |
| CVE-2024-32570 | Cornerstone [cornerstone] < 0.8.1 (closed) | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.1 | < 0.8.1 | 0.8.1 | 2024-04-16 | ✓ fixed in latest |
| CVE-2024-28002 | Cornerstone [cornerstone] < 0.8.1 (closed) | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.1 | < 0.8.1 | 0.8.1 | 2024-03-28 | ✓ fixed in latest |
How to fix it
Keep Cornerstone updated — 0.8.1 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- White Label CMS — 200000+ active installs — 94/100 (113) — max PHP 8.4
- FileBird – WordPress Media Library Folders & File Manager — 200000+ active installs — 94/100 (1120) — max PHP 8.4
- List category posts — 80000+ active installs — 94/100 (254) — max PHP 8.4
- Rich Table of Contents — 20000+ active installs — 82/100 (17) — max PHP <8.0
- Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types — 20000+ active installs — 98/100 (56) — max PHP 8.4
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.