Display Remote Posts Block

Display Remote Posts Block has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.

The most common weakness is Server-Side Request Forgery (SSRF), behind 1 of the records (100%).

The one issue recorded for Display Remote Posts Block has a vendor fix available, so running the current release closes it.

All of these findings were reported by theviper17y. Display Remote Posts Block is installed on roughly 800 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSMedium
6.4/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Display Remote Posts Block vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.4CVE-2025-47484

Display Remote Posts Block <= 1.1.0 - Authenticated (Contributor+) Server-Side Request Forgery

Read the full analysis

Vulnerability Records

1 records
Display Remote Posts Block banner
Latestv1.1.4

Display Remote Posts Block

Oliver Campion

Author

Oliver Campion

0.0(0)
0/100
Last Updated
2026-08-14 (29d ago)
Active Installs
800+
Downloads
16,013
Requires WP
5.0+
Requires PHP
7.0+
Tested up to
WP 7.1
Created
2021-02-23 (6y ago)

Display Remote Posts Block This plugin adds a block in the Gutenberg editor to allow you to display posts from a third party blog. Currently this plugin supports the following blog types … WordPress.org WordPress (self hosted with Jetpack installed) WordPress (self hosted) Blogger – An issue with feeds.feedburner.com is currently breaking Blogger compatibility Contact us in the Support Forum if you’d like us to add support for another type of blog.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C