Mark New Posts
Mark New Posts has one disclosed vulnerability in the WordSec catalog, all reported in 2024; it is fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Missing Authorization, behind 1 of the records (100%).
The one issue recorded for Mark New Posts has a vendor fix available, so running the current release closes it.
All of these findings were reported by Jingle Bells. Mark New Posts is installed on roughly 500 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.7.7.
CVE-2024-54311Mark New Posts <= 7.5.1 - Missing Authorization via save_options
Read the full analysisVulnerability Records
Mark New Posts
Author
i.lychkov
Highlight unread posts on your blog. Key features: Works right out of the box Uses cookies, no authorization required 4 different types of markers for highlighting posts (a “new” text label, an orange circle, etc.) Customizable background color for unread post titles There’s a setting to determine when a post should be considered read. You can pick one of the following: after it was opened after it was displayed in the post list after opening any page of the blog Functions available for theme developers: mnp_is_new_post($post) – check if a post is unread mnp_new_posts_count($query) – get unread posts count
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C