Content Blocks (Custom Post Widget)

Content Blocks (Custom Post Widget) has 6 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2026; all 6 are fixed as of September 2026. Their average CVSS score is 6.8, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 1 high. 2024 was the busiest year with 4 disclosures.

The most common weakness is Cross-Site Scripting, behind 5 of the records (83%). Other recurring categories include PHP Remote File Inclusion.

Every one of the 6 issues recorded for Content Blocks (Custom Post Widget) has a vendor fix available, so running the current release closes all known holes.

5 independent researchers contributed these findings, most of them (2) reported by lowol. Content Blocks (Custom Post Widget) is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSMedium
6.8/ 10
Patch Coverage100%
Open

0

Fixed

6

Get automatic notifications for all Content Blocks (Custom Post Widget) vulnerabilities before they are exploited.

Highest severity on recordCVSS 8.8CVE-2024-3564

Content Blocks (Custom Post Widget) <= 3.3.0 - Authenticated (Contributor+) Local File Inclusion via Shortcode

Read the full analysis

Vulnerability Records

6 records
Content Blocks (Custom Post Widget) banner
Latestv3.4.3

Content Blocks (Custom Post Widget)

Johan van der Wijk

Author

Johan van der Wijk

4.9(80)
98/100
Last Updated
2026-07-22 (2mo ago)
Active Installs
10,000+
Downloads
754,613
Requires WP
4.6+
Requires PHP
0+
Tested up to
WP 7.0.4
Created
2010-11-15 (16y ago)

The Content Blocks allows you to display the contents of a specific custom post in a widget on in the content area using a shortcode. Even though you could use the text widget that comes with the default WordPress install, this plugin has some major benefits: The Content Blocks plugin enables users to use the WYSIWYG editor for editing the content and adding images. If you are using the standard WordPress text widgets to display content on various areas of your template, this content can only be edited by users with administrator access. If you would like non-administrator accounts to modify the widget content, you can use this plugin to provide them access to the custom posts that provide the content for the widget areas. You can even use the featured image functionality to display them in a widget. The Content Blocks plugin is compatible with the WPML Multi-Language plugin and automatically shows the correct language in the widget area. The Content Blocks can be included in posts and pages using the built-in shortcode functionality. This plugin creates a &#8216;content_block’ custom post type. You can choose to either display the title on the page or use it to describe the contents and widget position of the content block. Note that these content blocks can only be displayed in the context of the page. I have added &#8216;public’ => false to the custom post type which means that it is not accessible outside the page context. To add content to a widget, drag it to the required position in the sidebar and select the title of the custom post in the widget configuration. Includes the following translations: Swedish (sv_SE) by Andreas Larsson Spanish (es_ES) by IBIDEM GROUP Portuguese (pt_BR) by Ronaldo Chevalier Polish (pl_PL) by Kuba Skublicki Dutch (nl_NL) by Johan van der Wijk Czech (cs_CZ) by Martin Kucera More translations are very welcome!

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C