Known vulnerabilities in Insert Pages
Insert Pages lets you embed any WordPress content (e.g., pages, posts, custom post types) into other WordPress content using the Shortcode API.
5Reported vulnerabilities
9.1Highest CVSS score
3.11.5Latest version
30,000+Active installs
What to do now
Update Insert Pages to 3.11.5 or later.
5 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2017-18586 | Critical | 2.5% | Before 3.2.4 | 3.2.4 |
August 22, 2019 |
| CVE-2022-4483 | Medium | 0.5% | Before 3.7.5 | 3.7.5 |
January 16, 2023 |
| CVE-2021-24850 | Medium | 0.6% | Before 3.7.0 | 3.7.0 |
November 17, 2021 |
| CVE-2021-24851 | Medium | 0.9% | Before 3.7.0 | 3.7.0 |
November 17, 2021 |
| CVE-2026-10089 | Medium | 0.4% | 0 to 3.11.4 (inclusive) | 3.11.5 |
July 2, 2026 |