W4 Post List
W4 Post List has 6 disclosed vulnerabilities in the WordSec catalog, reported between 2022 and 2023; all 6 are fixed as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 6.4 out of 10. 2023 was the busiest year with 4 disclosures.
The most common weakness is Cross-Site Scripting, behind 3 of the records (50%). Other recurring categories include Cross-Site Request Forgery (CSRF), Exposure Of Sensitive Information To An Unauthorized Actor.
Every one of the 6 issues recorded for W4 Post List has a vendor fix available, so running the current release closes all known holes.
3 independent researchers contributed these findings, most of them (2) reported by Erwan LR. W4 Post List is installed on roughly 3,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2023-0374W4 Post List <= 2.4.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block Options
Read the full analysisVulnerability Records

W4 Post List
Author
Shazzad Hossain Khan
W4 Post List builds the lists that WordPress core still can’t: posts grouped under year, month, category or author headings; category and term indexes; user directories; and combined Terms + Posts and Users + Posts lists. You control the output with a template of plain HTML and simple template tags, so the markup stays clean, semantic and completely yours. Place any list anywhere with the W4 Post List block, the [postlist id="123"] shortcode, or the classic widget. What can you build? Year/month archives — posts grouped under date headings Category, tag or custom taxonomy indexes — with or without each term’s posts listed underneath Author and user directories — list users by role, with avatars, bios and each user’s posts Filtered post lists — any post type, filtered by status, taxonomy terms, custom fields, dates, authors, parents and more Media lists — image and attachment lists by mime type Five list types Posts Terms Users Terms + Posts Users + Posts Query options (Posts) Post type, status and mime type Search keyword Include/exclude posts by ID, exclude the current post Filter by parent, author, taxonomy terms (tax query), custom fields (meta query) and dates (date query) Items per page, with multi-page pagination Group results by Year, month, or month + year Category, tag or any custom taxonomy Author Parent Order results by ID, title, slug, publish date, modified date, menu order, comment count, custom field value, or random Pagination Next/previous links or numeric navigation, with optional AJAX page loading Full control over the output Output is template-driven: every list has an HTML template with template tags like [post_title], [post_permalink], [featured_image], [post_author_name] and [post_meta key="..."]. Start from a ready-made template — cards, archives, category indexes, user directories — and tweak it, or write your own markup for pixel-perfect control. A live preview in the editor shows your changes before you save. If you want a drag-and-drop visual builder, this plugin isn’t that — it keeps you close to your own HTML, which is exactly why themes and developers like it. See the full template tag reference and live examples with copy-paste templates. Lightweight, independently measured WP Hive independently measures W4 Post List at 19 KB memory usage and +0.05 s page-speed impact — better than 99% of the plugins they test. No bundled frameworks, no frontend bloat. Privacy Policy W4 Post List uses Appsero SDK to collect some telemetry data upon user’s confirmation. This helps us to troubleshoot problems faster & make product improvements. Appsero SDK does not gather any data by default. The SDK only starts gathering basic telemetry data when a user allows it via the admin notice. We collect the data to ensure a great user experience for all our users. Integrating Appsero SDK DOES NOT IMMEDIATELY start gathering data, without confirmation from users in any case. Learn more about how Appsero collects and uses this data.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C