Posts in Page
Posts in Page has one disclosed vulnerability in the WordSec catalog, all reported in 2017; it is fixed as of September 2026. Their average CVSS score is 8.1, and the most serious one scores 8.1 out of 10. Severity breakdown: 0 critical and 1 high.
The most common weakness is PHP Remote File Inclusion, behind 1 of the records (100%).
The one issue recorded for Posts in Page has a vendor fix available, so running the current release closes it.
Posts in Page is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 5.2.26.
CVE-2017-18585Posts in Page <= 1.2.4 - Authenticated Directory Traversal leading to Local File Inclusion
Read the full analysisVulnerability Records

Posts in Page
Author
ivycat
Easily add one or more posts to any page using simple shortcodes. Supports categories, tags, custom post types, custom taxonomies, date ranges, post status, and much more. You can get all of the same functionality provided by this plugin by modifying your theme’s template files; this plugin just makes it easy for anyone to pull posts into other areas of the site without having to get their hands dirty with code. Plugin is depending upon your theme’s styling; version 1.x of this plugin does not contain native styles. This is a minimal plugin, function over form. Give us feedback, suggestions, bug reports, and any other contributions on the in the plugin’s GitHub repository.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C