Mark Posts

Mark Posts has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2022 and 2025; all 2 are fixed as of September 2026. Their average CVSS score is 4.5, and the most serious one scores 4.8 out of 10.

The most common weakness is Cross-Site Scripting, behind 1 of the records (50%). Other recurring categories include Missing Authorization.

Every one of the 2 issues recorded for Mark Posts has a vendor fix available, so running the current release closes all known holes.

2 independent researchers contributed these findings, one record each. Mark Posts is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSMedium
4.5/ 10
Patch Coverage100%
Open

0

Fixed

2

Get automatic notifications for all Mark Posts vulnerabilities before they are exploited.

Highest severity on recordCVSS 4.8CVE-2022-0958

Mark Posts <= 2.0.0 - Admin+ Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

2 records
Mark Posts banner
Latestv2.2.6

Mark Posts

flymke

Author

flymke

4.8(10)
96/100
Last Updated
2026-08-31 (13d ago)
Active Installs
1,000+
Downloads
17,910
Requires WP
4.1+
Requires PHP
7.0+
Tested up to
WP 7.1
Created
2014-04-04 (13y ago)

Mark Posts plugin provides an easy way to mark and highlight posts, pages and posts of custom post types within the WordPress admin posts overview. Features Set custom marker categories and colors Assign marker categories to posts/pages or any other post type View the highlighted posts within the posts overview Quick edit, bulk edit and/or edit all markers at once Dashboard widget with marker status count Optional custom setup via filters (check our wiki for instructions) Live Demo Try out the features of Mark Posts on the WordPress playground. Support Active development of this plugin is handled on GitHub. Always feel free to raise an issue.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C