← WordPress Vulnerabilities
WordPress security by component

VI: Include Post By

VI: Include Post By is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Apr 15, 2026; the highest CVE/CNA score is 6.4.

Plugin slug: vi-include-post-by

CVE-2026-5717: VI: Include Post By: Cross-site scripting

VI: Include Post By is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 0.4.200706.

PublishedApr 15, 2026
Known safe version> 0.4.200706
Safe version
Apr 15, 2026 CVE-2026-5717
VI: Include Post By: Cross-site scripting
VI: Include Post By is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 0.4.200706.
> 0.4.200706
CVE6.4
NVDPending