plugin

Related Post Vulnerabilities

7 known security issues reported for the Related Post WordPress plugin. Most recent disclosed Mar 7, 2025.

3 medium

Running Related Post on your site? Check whether your installed version is affected.

Scan your site free

Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins [related-post] < 2.0.60

unknown

[en] The Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including 2.0.59. This is due to missing nonce validation on a function. This makes it possible for unauthenticated attackers...

Affected:
up to 2.0.60
Fixed in:
2.0.60
Disclosed:
Mar 7, 2025

CVE-2024-12634 on NVD →

Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins <= 2.0.59 - Cross-Site Request Forgery to Stored Cross-Site Scripting

medium

The Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including 2.0.59. This is due to missing nonce validation on a function. This makes it possible for unauthenticated attackers to i...

CVSS:
6.1
Affected:
2.0.59 – 2.0.59
Fixed in:
2.0.60
Disclosed:
Mar 6, 2025

CVE-2024-12634 on NVD →

Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins [related-post] < 2.0.59

unknown

[en] The Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.58 via the wp_ajax_nopriv_related_post_ajax_get_post_ids AJAX action. This makes it possible for unauthent...

Affected:
up to 2.0.59
Fixed in:
2.0.59
Disclosed:
Dec 5, 2024

CVE-2024-10937 on NVD →

Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins <= 2.0.58 - Sensitive Information Exposure

medium

The Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.58 via the wp_ajax_nopriv_related_post_ajax_get_post_ids AJAX action. This makes it possible for unauthenticate...

CVSS:
5.3
Affected:
up to 2.0.58
Fixed in:
2.0.59
Disclosed:
Dec 4, 2024

CVE-2024-10937 on NVD →

Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins [related-post] < 2.0.54

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Related Post allows Stored XSS.This issue affects Related Post: from n/a through 2.0.53.

Affected:
up to 2.0.54
Fixed in:
2.0.54
Disclosed:
Feb 1, 2024

CVE-2023-51666 on NVD →

Related Post <= 2.0.53 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Related Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 2.0.53 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level...

CVSS:
6.4
Affected:
up to 2.0.53
Fixed in:
2.0.54
Disclosed:
Nov 30, 2023

CVE-2023-51666 on NVD →

Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins [related-post] < 2.0.54

unknown

The Related Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 2.0.53 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level...

Affected:
up to 2.0.54
Fixed in:
2.0.54
Disclosed:
Nov 30, 2023

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database