Custom Related Posts
Custom Related Posts has 3 disclosed vulnerabilities in the WordSec catalog, all reported in 2025; all 3 are fixed as of September 2026. Their average CVSS score is 5.7, and the most serious one scores 6.4 out of 10. 2025 was the busiest year with 3 disclosures.
The most common weakness is Cross-Site Scripting, behind 1 of the records (33%). Other recurring categories include Exposure Of Sensitive Information To An Unauthorized Actor, Missing Authorization.
Every one of the 3 issues recorded for Custom Related Posts has a vendor fix available, so running the current release closes all known holes.
3 independent researchers contributed these findings, one record each. Custom Related Posts is installed on roughly 3,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2025-46227Custom Related Posts <= 1.7.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Custom Related Posts
Author
Brecht
Custom Related Posts is a user friendly plugin for manually adding related posts to any of your posts, pages or custom post types. You have full control over those related links, choosing for yourself if they go both ways. An overview of the features: Set which post types the plugin is active for yourself Easily define relations in one or both ways on the post edit page Display related posts with a shortcode, widget or block Optionally show featured images in any size Import from XML using post IDs Compatible with the Classic Editor and Gutenberg Block Editor Need help? Check out our documentation! This plugin is under active development. Any feature requests are welcome!
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C