Mark Posts
Mark Posts has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2022 and 2025; all 2 are fixed as of September 2026. Their average CVSS score is 4.5, and the most serious one scores 4.8 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (50%). Other recurring categories include Missing Authorization.
Every one of the 2 issues recorded for Mark Posts has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. Mark Posts is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2022-0958Mark Posts <= 2.0.0 - Admin+ Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Mark Posts
Author
flymke
Mark Posts plugin provides an easy way to mark and highlight posts, pages and posts of custom post types within the WordPress admin posts overview. Features Set custom marker categories and colors Assign marker categories to posts/pages or any other post type View the highlighted posts within the posts overview Quick edit, bulk edit and/or edit all markers at once Dashboard widget with marker status count Optional custom setup via filters (check our wiki for instructions) Live Demo Try out the features of Mark Posts on the WordPress playground. Support Active development of this plugin is handled on GitHub. Always feel free to raise an issue.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C