Client Showcase
Client Showcase has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Client Showcase has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by SOPROBRO. Client Showcase is installed on roughly 30 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 4.7.35.
CVE-2025-31737Client Showcase <= 1.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Client Showcase
Author
dxladner
Display your Clients with pride. This plugin displays your client’s logo in a page, post using a shortcode or use the custom widget. Attach your client’s website URL to the Logo for added information. Administrator enters their clients using a custom post type. They can enter the client’s name/title, logo and their website url. Then using a shortcode you can display your Clients Logo on a page or post. This plugin also comes with a Custom Widget. Just find the widget called ‘Client Showcase’, drag and drop into your themes widget sections. Simple way to display your clients to show your expertise. Do not have Clients. You can use this plugin for displaying multiple different options. Use your creativity. NEW FEATURES: Drag N Drop Ordering and Display your List Option. Using a simple Drag N Drop option, you can arrange your clients in any particular order you choose. Also, you can choose whether to display your Clients Horizontally or Vertically. For complete instructions for the NEW FEATURES, please read the complete documentation located at our website Hyperdrive Designs: Client Showcase Documentation. If you decide to upgrade the plugin, be sure to read the new documentation as the settings have changed.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C