Blog-in-Blog
Blog-in-Blog has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2023; all 2 are fixed as of September 2026. Their average CVSS score is 5.8, and the most serious one scores 7.2 out of 10. Severity breakdown: 0 critical and 1 high. 2023 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Scripting, behind 1 of the records (50%). Other recurring categories include Path Traversal.
Every one of the 2 issues recorded for Blog-in-Blog has a vendor fix available, so running the current release closes all known holes.
All of these findings were reported by István Márton. Blog-in-Blog is installed on roughly 800 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.7.7.
CVE-2023-2435Blog-in-Blog <= 2.0.0 - Authenticated (Editor+) Local File Inclusion via Shortcode
Read the full analysisVulnerability Records
Blog-in-Blog
Author
timhodson
Blog-in-Blog allows you to use the WordPress platform for it’s CMS features, but still have a blog page on your site. Posts selected by category, post_type, tag or any combination thereof, can be used to feed the ‘special’ blog page, and can optionally be hidden from the home page. You can have more than one category hidden from the homepage (not post_types or tags). You can also use this plugin to show posts on the same page from different categories, post_types or tags, but in several different blocks and using different layout templates. If you find this plugin useful (especially if it gets you out of a fix in a commercial setting), please feel free to leave feedback via the donate button. I am grateful for those people who have already bought me a beer 🙂 Important: In previous versions of the Blog-in-Blog plugin you might have edited bib_post_template.tpl. If you are upgrading, we will copy this to a textbox so you can edit the template from the plugin page. The bib_post_template.pl file is no longer used and may vanish in a future release.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C