Plugin Vulnerability Hub
Plugin 3 known issues Latest disclosed Mar 18, 2026

Info Cards – Add Text and Media in Card Layouts Vulnerabilities

Review known vulnerability records for the WordPress plugin Info Cards – Add Text and Media in Card Layouts (`info-cards`), including severity, CVE references, affected versions, and patch status.

Known Records
3
High or Critical
0
Linked CVEs
3
Last Updated
Mar 18, 2026
Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for Info Cards – Add Text and Media in Card Layouts so operators can quickly confirm whether a disclosed issue maps to the installed slug and version range.

Patch Visibility
3 records include a published patch path.
Severity Mix
0 critical and 0 high severity findings.
Reference Workflow
Jump from the hub into the full report when you need remediation notes, CVSS vector details, or source references.
Known Vulnerabilities

Reports for Info Cards – Add Text and Media in Card Layouts

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes CVE-2026-4120
Info Cards <= 2.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attributes

The Info Cards – Add Text and Media in Card Layouts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'btnUrl' parameter within the Info Cards block in all versions up to, and including, 2.0.7. This is due to insufficient input validation on URL schemes, s...

Published
Mar 18, 2026
Patched Release
2.0.8
Affected Versions
Versions up to 2.0.7
Next Step
Update to 2.0.8 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-54711
Info Cards <= 1.0.11 - Missing Authorization

The Info Cards – Add Text and Media in Card Layouts plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.0.11. This makes it possible for authenticated attackers, with Subscriber-level ac...

Published
Aug 26, 2025
Patched Release
2.0.0
Affected Versions
Versions up to 1.0.11
Next Step
Update to 2.0.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-26945
Info Cards – Gutenberg block for creating Beautiful Cards <= 1.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Info Cards – Gutenberg block for creating Beautiful Cards plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,...

Published
Feb 23, 2025
Patched Release
1.0.6
Affected Versions
Versions up to 1.0.5
Next Step
Update to 1.0.6 or newer if supported.