April's Call Posts
April's Call Posts has one disclosed vulnerability in the WordSec catalog, all reported in 2024; it is fixed as of September 2026. Their average CVSS score is 5.4, and the most serious one scores 5.4 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for April's Call Posts has a vendor fix available, so running the current release closes it.
All of these findings were reported by SOPROBRO. April's Call Posts is installed on roughly 20 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
CVE-2024-53730April's Call Posts <= 2.1.1 - Cross-Site Request Forgery to Cross-Site Scripting
Read the full analysisVulnerability Records

April's Call Posts
Author
springthistle
This plugin is useful if you are using lots of posts in a variety of ways on your website, i.e. not just on your homepage and not just separated out by categories. For example, You may have a blog with lots of information on upcoming events and lots of announcements. You have a variety of people who come to your blog looking for different information, and it’s hard for them to filter through everything. You can have a “Cats” page on which you talk about your stance on cats, and use [ahs_callposts] to also call in a list of posts in the “cats” category, perhaps only the most recent 10, perhaps just titles, perhaps displaying just excerpts, perhaps displaying an image for each post. Then have a separate page for the “dogs” category. Etc! Features Specify category Specify number of posts Specify content style Specify random order Specify multiple columns Create your own template (NEW as of 2.0) … and more Choose global default settings that can be overridden for any individual instance of the shortcode.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C