PLUGIN SECURITY
Is Custom Post Type Ui safe?
Admin UI for creating custom content types like post types and taxonomies
What this plugin does
- Slug:
custom-post-type-ui - Author: webdevstudios
- 1000000+ active installs
- 92/100 rating (276 reviews on wordpress.org)
- 24632349 all-time downloads
- On WordPress.org since 2010-02-26
content typescustom post typespost typetaxonomytypes
Maintenance status
- Latest known version: 1.19.3
- Last updated: 2026-07-14 3:37pm GMT
- Tested up to WordPress: 7.0.4
- Requires PHP: 7.4+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
3 known CVEs on file for Custom Post Type Ui. Reported between 2020 and 2025.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2025-14056 | Custom Post Type UI [custom-post-type-ui] < 1.18.2 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.4 | < 1.18.2 | 1.18.2 | 2025-12-12 | ✓ fixed in latest |
| CVE-2025-12826 | Custom Post Type UI [custom-post-type-ui] < 1.18.1 | Missing Authorization | Medium 4.8 | < 1.18.1 | 1.18.1 | 2025-12-03 | ✓ fixed in latest |
| — | Custom Post Type UI [custom-post-type-ui] < 1.13.5 | — | Unknown | < 1.13.5 | 1.13.5 | 2023-03-30 | ✓ fixed in latest |
| CVE-2023-1623 | Custom Post Type UI [custom-post-type-ui] < 1.13.5 | Cross-Site Request Forgery (CSRF) | Medium 6.5 | < 1.13.5 | 1.13.5 | 2023-03-28 | ✓ fixed in latest |
| — | Custom Post Type UI [custom-post-type-ui] < 1.7.4 | — | Unknown | < 1.7.4 | 1.7.4 | 2020-03-18 | ✓ fixed in latest |
| — | Custom Post Type UI [custom-post-type-ui] < 1.7.4 | — | Unknown | < 1.7.4 | 1.7.4 | 2020-03-17 | ✓ fixed in latest |
| — | Custom Post Type UI [custom-post-type-ui] < 1.7.4 | — | Unknown | < 1.7.4 | 1.7.4 | — | ✓ fixed in latest |
| — | Custom Post Type UI < 1.7.4 - CSRF to Stored XSS | — | Unknown | < 1.7.4 | 1.7.4 | — | ✓ fixed in latest |
How to fix it
Keep Custom Post Type Ui updated — 1.19.3 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Meta Box — 500000+ active installs — 96/100 (165) — max PHP 8.4
- Pods – Custom Content Types and Fields — 100000+ active installs — 96/100 (418) — max PHP 8.4
- Sydney Toolbox — 50000+ active installs — 46/100 (15) — max PHP 8.4
- CMS Tree Page View – Reorder Pages with a Drag-and-Drop Tree — 50000+ active installs — 98/100 (365)
- Essential Content Types — 20000+ active installs — 74/100 (3)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.