IndieBlocks
IndieBlocks has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2025; all 2 are fixed as of September 2026. Their average CVSS score is 6.8, and the most serious one scores 7.2 out of 10. Severity breakdown: 0 critical and 1 high. 2025 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Scripting, behind 1 of the records (50%). Other recurring categories include Server-Side Request Forgery (SSRF).
Every one of the 2 issues recorded for IndieBlocks has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. IndieBlocks is installed on roughly 100 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
CVE-2025-31009IndieBlocks <= 0.13.1 - Unauthenticated Server-Side Request Forgery
Read the full analysisVulnerability Records
IndieBlocks
Author
Jan Boddez
Use blocks, and, optionally, “short-form” post types to easily “IndieWebify” your WordPress site. IndieBlocks registers several blocks (Bookmark, Like, Reply, and Repost, as well as the older Context block) that take a URL and output corresponding microformatted HTML. In combination with a microformats-compatible theme, these help ensure microformats clients are able to determine a post’s type. It also comes with “short-form” (Note and Like) custom post types, and a (somewhat experimental) option to add microformats to (all!) block-based themes. These microformats, in combination with the Webmention protocol, allow for rich cross-site conversations. IndieBlocks comes with its own Webmention implementation, but a separate plugin can be used, too. IndieBlocks also registers several “theme” blocks (Facepile, Location, Syndication, and Link Preview), to be used in “block theme” templates.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C