cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forcustom-related-posts custom-related-posts

Direction: ascending
Feb 03, 2025

Custom Related Posts # CVE-2024-12825

CVE, Research URL

CVE-2024-12825

Application

Custom Related Posts

Date
Feb 01, 2025
Research Description
The Custom Related Posts plugin for WordPress is vulnerable to unauthorized access & modification of data due to a missing capability check on three AJAX actions in all versions up to, and including, 1.7.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to search posts and link/unlink relations.
Affected versions
max 1.7.4.
Status
vulnerable
Apr 24, 2025

Custom Related Posts # CVE-2025-46227

CVE, Research URL

CVE-2025-46227

Application

Custom Related Posts

Date
Apr 22, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brecht Custom Related Posts allows Stored XSS. This issue affects Custom Related Posts: from n/a through 1.7.4.
Affected versions
max 1.7.5.
Status
vulnerable
Jan 10, 2026

Custom Related Posts # CVE-2025-68033

CVE, Research URL

CVE-2025-68033

Application

Custom Related Posts

Date
Jan 05, 2026
Research Description
Insertion of Sensitive Information Into Sent Data vulnerability in Brecht Custom Related Posts allows Retrieve Embedded Sensitive Data.This issue affects Custom Related Posts: from n/a through 1.8.0.
Affected versions
max 1.8.0.
Status
vulnerable