Posts in Page

Posts in Page has one disclosed vulnerability in the WordSec catalog, all reported in 2017; it is fixed as of September 2026. Their average CVSS score is 8.1, and the most serious one scores 8.1 out of 10. Severity breakdown: 0 critical and 1 high.

The most common weakness is PHP Remote File Inclusion, behind 1 of the records (100%).

The one issue recorded for Posts in Page has a vendor fix available, so running the current release closes it.

Posts in Page is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 5.2.26.

Strategic Overview

Avg CVSSHigh
8.1/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Posts in Page vulnerabilities before they are exploited.

Highest severity on recordCVSS 8.1CVE-2017-18585

Posts in Page <= 1.2.4 - Authenticated Directory Traversal leading to Local File Inclusion

Read the full analysis

Vulnerability Records

1 records
Posts in Page banner
Latestv1.4.4

Posts in Page

ivycat

Author

ivycat

4.4(86)
88/100
Last Updated
2019-05-13 (7y ago)
Active Installs
10,000+
Downloads
379,113
Requires WP
3.0+
Requires PHP
0+
Tested up to
WP 5.2.26
Created
2012-02-27 (15y ago)

Easily add one or more posts to any page using simple shortcodes. Supports categories, tags, custom post types, custom taxonomies, date ranges, post status, and much more. You can get all of the same functionality provided by this plugin by modifying your theme’s template files; this plugin just makes it easy for anyone to pull posts into other areas of the site without having to get their hands dirty with code. Plugin is depending upon your theme’s styling; version 1.x of this plugin does not contain native styles. This is a minimal plugin, function over form. Give us feedback, suggestions, bug reports, and any other contributions on the in the plugin’s GitHub repository.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C