WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Blog Designer Pack – Blog, Post Grid, Post Slider, Post Carousel, Category Post, News

News & Blog plugin for post grid, post slider, post carousel, post filter, masonry, ticker & list category posts using shortcode, Elementor & Divi.

3Reported vulnerabilities
9.8Highest CVSS score
4.0.11Latest version
30,000+Active installs

What to do now

Update Blog Designer Pack – Blog, Post Grid, Post Slider, Post Carousel, Category Post, News to 4.0.1 or later. 3 of these have a fixed version available. Updating resolves them.

Plugin last updated: April 4, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2023-5815 Critical 9.8 4.3% 3.4.1 and earlier 3.4.2 November 22, 2023
CVE-2025-31082 Critical 9.8 0.8% 4.0 and earlier 4.0.1 April 1, 2025
CVE-2022-4792 Medium 5.4 0.4% Before 3.3 3.3 January 30, 2023

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.