Plugin Vulnerability Hub
Plugin 2 known issues Latest disclosed Apr 08, 2026

Post Blocks & Tools Vulnerabilities

Review known vulnerability records for the WordPress plugin Post Blocks & Tools (`bnm-blocks`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2026-5711 and CVE-2025-11828, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
2
High or Critical
0
Patch Coverage
100%
Last Updated
Apr 08, 2026
Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for Post Blocks & Tools so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
2 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
0 critical and 0 high severity findings.
Recent CVEs
CVE-2026-5711 and CVE-2025-11828
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

Known Vulnerabilities

Reports for Post Blocks & Tools

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes CVE-2026-5711
Post Blocks & Tools <= 1.3.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'sliderStyle' Block Attribute

The Post Blocks & Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sliderStyle' block attribute in the Posts Slider block in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping on user supplied attrib...

Published
Apr 08, 2026
Patched Release
1.3.1
Affected Versions
Versions up to 1.3.0
Next Step
Update to 1.3.1 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-11828
Magazine Companion <= 1.2.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Magazine Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'headerHtmlTag' attribute in the bnm-blocks/featured-posts-1 block in all versions up to, and including, 1.2.3. This is due to insufficient input sanitization and output escaping when...

Published
Nov 10, 2025
Patched Release
1.2.4
Affected Versions
Versions up to 1.2.3
Next Step
Update to 1.2.4 or newer if supported.