Hyperlink Group Block
Hyperlink Group Block has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2025; all 2 are fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 2 of the records (100%).
Every one of the 2 issues recorded for Hyperlink Group Block has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. Hyperlink Group Block is installed on roughly 7,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2025-31885Hyperlink Group Block <= 2.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Hyperlink Group Block
Author
Daniel Floeter
Combine blocks into a group wrapped with an hyperlink (<a>). After inserting a Hyperlink Group Block, a Block inserter icon will be displayed to allow you to add new Blocks inside that Hyperlink Group Block. Tip Top Press We’re Tip Top Press and create Gutenberg Blocks for WordPress. If you want to know about what we’re working on and you are interested in backgrounds then you can read all newes storys on our blog. Grouping Existing Blocks It’s also possible to group existing Blocks. Select the Blocks which should be grouped with a Hyperlink. The Block Toolbar will appear. Click on the Block icon and select the Hyperlink Block to transform the selected Blocks to an Hyperlink Block with some InnerBlocks. Advanced On the Advanced Tab set the link’s target, rel, title and aria-label attributes. Features Wrap Blocks with a hyperlink Use link from Query Loop Block Transform Blocks into a group wrapped with an HTML anchor tag (<a>) Set the link href attribute Set rel, title and aria-label attributes Option open in a new window and set tab name to open in the same tab Set hover background color Inner anchor elements are automatically deleted Contribute While using this plugin if you find any bug or any conflict, please submit an issue at Github (If possible with a pull request).
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C