PLUGIN SECURITY

Is Contextual Related Posts safe?

Keep visitors on your site longer with intelligent, fast-loading, contextually related posts. Block, shortcode, custom post type and widget ready.

What this plugin does

  • Slug: contextual-related-posts
  • Author: Ajay
  • 50000+ active installs
  • 96/100 rating (201 reviews on wordpress.org)
  • 2726890 all-time downloads
  • On WordPress.org since 2009-01-21

contextual related postsrelatedrelated postsseosimilar posts

Maintenance status

  • Latest known version: 4.3.0
  • Last updated: 2026-08-17 6:14pm GMT
  • Tested up to WordPress: 7.1
  • Requires PHP: 7.4+
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

6 known CVEs on file for Contextual Related Posts. Reported between 2013 and 2026.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-2986 Contextual Related Posts [contextual-related-posts] < 4.2.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 4.2.2 4.2.2 2026-04-17 ✓ fixed in latest
CVE-2026-32565 Contextual Related Posts [contextual-related-posts] < 4.2.2 Missing Authorization Medium 5.3 < 4.2.2 4.2.2 2026-03-18 ✓ fixed in latest
CVE-2025-47506 Contextual Related Posts [contextual-related-posts] < 4.0.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 4.0.3 4.0.3 2025-05-07 ✓ fixed in latest
Contextual Related Posts [contextual-related-posts] < 3.3.2 Unknown < 3.3.2 3.3.2 2023-02-21 ✓ fixed in latest
Contextual Related Posts [contextual-related-posts] < 3.3.2 Unknown < 3.3.2 3.3.2 2023-02-20 ✓ fixed in latest
Contextual Related Posts [contextual-related-posts] < 3.3.2 Unknown < 3.3.2 3.3.2 2023-02-20 ✓ fixed in latest
Contextual Related Posts [contextual-related-posts] < 3.3.1 Unknown < 3.3.1 3.3.1 2023-01-06 ✓ fixed in latest
CVE-2023-0252 Contextual Related Posts [contextual-related-posts] < 3.3.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.3.1 3.3.1 2023-01-05 ✓ fixed in latest
+ 7 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
Contextual Related Posts [contextual-related-posts] < 2.9.4 Unknown < 2.9.4 2.9.4 2020-11-19 ✓ fixed in latest
Contextual Related Posts [contextual-related-posts] < 2.9.4 Unknown < 2.9.4 2.9.4 2020-11-19 ✓ fixed in latest
CVE-2014-3937 Contextual Related Posts [contextual-related-posts] < 1.8.10.2 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Unknown < 1.8.10.2 1.8.10.2 2014-03-06 ✓ fixed in latest
CVE-2013-2710 Contextual Related Posts [contextual-related-posts] < 1.8.7 Cross-Site Request Forgery (CSRF) Unknown < 1.8.7 1.8.7 2013-03-26 ✓ fixed in latest
Contextual Related Posts [contextual-related-posts] < 2.9.4 Unknown < 2.9.4 2.9.4 ✓ fixed in latest
Contextual Related Posts < 2.9.4 - CSRF Nonce Validation Bypass Unknown < 2.9.4 2.9.4 ✓ fixed in latest
CVE-2023-0252 Contextual Related Posts < 3.3.1 - Contributor+ Stored XSS Unknown < 3.3.1 3.3.1 ✓ fixed in latest

How to fix it

Keep Contextual Related Posts updated — 4.3.0 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.