Display Remote Posts Block
Display Remote Posts Block has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Server-Side Request Forgery (SSRF), behind 1 of the records (100%).
The one issue recorded for Display Remote Posts Block has a vendor fix available, so running the current release closes it.
All of these findings were reported by theviper17y. Display Remote Posts Block is installed on roughly 800 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2025-47484Display Remote Posts Block <= 1.1.0 - Authenticated (Contributor+) Server-Side Request Forgery
Read the full analysisVulnerability Records

Display Remote Posts Block
Author
Oliver Campion
Display Remote Posts Block This plugin adds a block in the Gutenberg editor to allow you to display posts from a third party blog. Currently this plugin supports the following blog types … WordPress.org WordPress (self hosted with Jetpack installed) WordPress (self hosted) Blogger – An issue with feeds.feedburner.com is currently breaking Blogger compatibility Contact us in the Support Forum if you’d like us to add support for another type of blog.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C