Custom Query Blocks
Custom Query Blocks has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2026; all 3 are fixed as of September 2026. Their average CVSS score is 6.0, and the most serious one scores 6.4 out of 10. 2024 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Scripting, behind 2 of the records (67%). Other recurring categories include Missing Authorization.
Every one of the 3 issues recorded for Custom Query Blocks has a vendor fix available, so running the current release closes all known holes.
3 independent researchers contributed these findings, one record each. Custom Query Blocks is installed on roughly 700 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2026-39575Custom Query Blocks <= 5.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Custom Query Blocks
Author
Ronald Huereca
Plugin Up for Adoption Before Closure Custom Query Blocks will be removed / deprecated from WordPress.org on October 1, 2026 if I can’t find a new owner . Please find a replacement before the closure date. Adoption Form | GitHub A WordPress plugin for displaying posts and terms (e.g., categories) using a Gutenberg block. Works well with posts, pages, custom post types, taxonomies, and terms. Bonus: archive mapping. Archive Pages Pro is here: Map post types, terms, authors, and more to pages. Learn more about Archive Pages Pro Map your post type archives to a page for customization of the post type archive page. Map your category archives to a page for customization of the term archive page. Map your 404 template to a page and easily customize your 404 page. View Documentation and Overview The plugin currently has three blocks: Custom Post Types Block Term (Category) Grid Block Featured Posts by Category Block Post Type Archive Mapping This plugin allows you to map your custom post type archive pages. Just create a page and go to Settings->Reading to set the page for your archive. Ensure your post types have has_archive set to true. Select a Public page to use as your post type archive page. View the archive and you will see the page content instead of the archive content. Use page templates on your pages for flexibility. Custom Gutenberg block for showing your posts. Term Archive Mapping This plugin also allows you to map your term archives to a page. Just create a page and go edit your term to set the archive page. Create a public page to use as your term archive. Visit the edit term page and select the page. View the term and you will see your selected page. Use Gutenberg on your public page to customize the archive. 404 Page Mapping This plugin allows you to map a page to your 404 template, so you can customize a 404 page as needed. Development is on GitHub Development is on GitHub Archive Pages Pro Archive Pages Pro has all the mapping feature of this plugin and more. You can map post types, terms, authors, and more to pages. Learn more about Archive Pages Pro
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C