Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts <= 3.0.12 - Authenticated (Administrator+) PHP Object Injection
Smart Post – Post Grid, Post Carousel, Post Slider Gutenberg Blocks for Blog & News
Minimum safe version
3.0.13
Update to 3.0.13 or later to address 7 fixable vulnerabilities
Latest available4.0.1 ✓
N/A
2026-04-13< 3.0.13
Medium 4.8
2025-05-15< 3.0.1
WordPress Post Grid, Post Carousel, & List Category Posts – by Smart Post Show Plugin <= 3.0.0 is vulnerable to Cross Site Scripting (XSS)
Medium 6.1
2025-05-19< 2.4.28
WordPress Post Grid, Post Carousel, & List Category Posts – by Smart Post Show Plugin < 2.4.28 is vulnerable to Cross Site Scripting (XSS)
N/A
< 2.3.5
Post Carousel < 2.3.5 - CSRF Bypass / Unauthorised AJAX Calls
N/A
2023-01-06< 2.3.5
WordPress Post Grid, Post Carousel, & List Category Posts – by Smart Post Show Plugin < 2.3.5 is vulnerable to Cross Site Request Forgery (CSRF)
Medium 5.4
2023-01-30< 2.4.19
CVE-2023-0097
N/A
2021-08-16< 2.3.5
Post Carousel < 2.3.5 - Missing Capabilities Check