
CBX Bookmark & Favorite Security & Risk Analysis
wordpress.org/plugins/cbxwpbookmarkBookmark and Favorite plugin for WordPress with category/list support.
Is CBX Bookmark & Favorite Safe to Use in 2026?
Generally Safe
Score 89/100CBX Bookmark & Favorite has a strong security track record. Known vulnerabilities have been patched promptly.
The cbxwpbookmark v2.0.6 plugin exhibits a mixed security posture. While it demonstrates good practices in SQL query preparation and output escaping, a significant concern arises from its large attack surface, particularly the 15 unprotected AJAX handlers. This lack of authorization checks on numerous entry points is a major weakness.
The taint analysis reveals one flow with an unsanitized path, indicating a potential for vulnerabilities, though it's classified as critical/high severity. The plugin's history is concerning, with 6 known CVEs, including one critical and five medium-severity vulnerabilities, predominantly involving missing authorization, XSS, and SQL injection. The fact that the last vulnerability was in 2026 is alarming and suggests a pattern of past security issues that could be indicative of ongoing development challenges or a lack of robust security auditing.
In conclusion, the plugin's strengths lie in its secure handling of SQL and output, but these are overshadowed by critical weaknesses in authorization for its AJAX endpoints and a history of significant vulnerabilities. The presence of unprotected AJAX handlers combined with past critical vulnerabilities points to a moderate to high risk.
Key Concerns
- 15 unprotected AJAX handlers
- 1 flow with unsanitized paths (critical/high severity)
- History of 1 critical CVE
- History of 5 medium CVEs
- Large attack surface without auth checks
CBX Bookmark & Favorite Security Vulnerabilities
CVEs by Year
Severity Breakdown
6 total CVEs
CBX Bookmark & Favorite <= 2.0.4 - Authenticated (Subscriber+) SQL Injection via `orderby` Parameter
CBX Bookmark & Favorite <= 2.0.1 - Missing Authorization
CBX Bookmark & Favorite <= 1.7.21 - Authenticated (Contributor+) Stored Cross-Site Scripting
CBX Bookmark & Favorite <= 1.7.20 - Authenticated (Administrator+) SQL Injection
CBX Bookmark & Favorite <= 1.7.13 - Authenticated (Contributor+) Stored Cross-Site Scripting
CBX Bookmark & Favorite <= 1.6.8 - Reflected Cross-Site Scripting
CBX Bookmark & Favorite Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
CBX Bookmark & Favorite Attack Surface
AJAX Handlers 15
Shortcodes 5
WordPress Hooks 57
Maintenance & Trust
CBX Bookmark & Favorite Maintenance & Trust
Maintenance Signals
Community Trust
CBX Bookmark & Favorite Alternatives
Favorites
favorites
Favorites for any post type. Easily add favoriting/liking, wishlists, or any other similar functionality using the developer-friendly API.
Slickstream: Engagement and Conversions
slick-engagement
Use Slickstream to upgrade your site search. Get beautiful as-you-type search, relevant content recommendations, user favorites and more!
Admin Bookmarks
my-admin-bookmarks
Bookmark your favorite posts, pages or custom post types within the WordPress admin
Favorite Post
favorite-post
This is a simple yet another favorite post plugin.
DBWD Bookmark Page
dbwd-bookmark-page
Adds a "Bookmark this Page" button to your header WITHOUT editing your theme - Firefox and IE tested.
CBX Bookmark & Favorite Developer Profile
9 plugins · 3K total installs
How We Detect CBX Bookmark & Favorite
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cbxwpbookmark/assets/css/frontend.css/wp-content/plugins/cbxwpbookmark/assets/css/main.css/wp-content/plugins/cbxwpbookmark/assets/css/style.css/wp-content/plugins/cbxwpbookmark/assets/js/frontend.js/wp-content/plugins/cbxwpbookmark/assets/js/main.js/wp-content/plugins/cbxwpbookmark/assets/js/public.js/wp-content/plugins/cbxwpbookmark/assets/js/frontend.js/wp-content/plugins/cbxwpbookmark/assets/js/main.js/wp-content/plugins/cbxwpbookmark/assets/js/public.jscbxwpbookmark/assets/css/frontend.css?ver=cbxwpbookmark/assets/css/main.css?ver=cbxwpbookmark/assets/css/style.css?ver=cbxwpbookmark/assets/js/frontend.js?ver=cbxwpbookmark/assets/js/main.js?ver=cbxwpbookmark/assets/js/public.js?ver=HTML / DOM Fingerprints
cbx-bookmark-containercbx-bookmark-btncbx-bookmark-itemcbx-bookmark-listdata-cbx-bookmarkcbx_bookmark_ajax_object/wp-json/cbxwpbookmark/v1/bookmark