Medium 6.4
2026-04-18< 3.4.1
CVE-2026-0894
Minimum safe version
3.4.1
Update to 3.4.1 or later to address 6 fixable vulnerabilities
CVE-2026-0894
Content Blocks (Custom Post Widget) <= 3.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via content Parameter
CVE-2024-44051
WordPress Content Blocks (Custom Post Widget) Plugin <= 3.3.0 is vulnerable to Local File Inclusion
CVE-2024-3565
CVE-2024-34566