
ACF Recent Posts Widget Security & Risk Analysis
wordpress.org/plugins/acf-recent-posts-widgetACF Recent Posts Widget (ACFRPW) is a WordPress plugin which adds a custom, extended Recent Posts Widget - with ACF and Meta Keys support
Is ACF Recent Posts Widget Safe to Use in 2026?
Use With Caution
Score 63/100ACF Recent Posts Widget has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "acf-recent-posts-widget" plugin, version 5.9.3, exhibits a mixed security posture. While it demonstrates good practices in avoiding dangerous functions, raw SQL queries, file operations, and external HTTP requests, significant concerns remain. The low percentage of properly escaped output (18%) is a critical weakness, suggesting a high likelihood of Cross-Site Scripting (XSS) vulnerabilities. This is further corroborated by its vulnerability history, which includes a medium-severity XSS vulnerability, the last of which was reported relatively recently. The absence of any reported taint flows in the static analysis, while seemingly positive, could be due to limitations in the analysis tool or the specific way user input is handled. The plugin's overall security is compromised by its output escaping issues and its history of XSS vulnerabilities. Despite a generally clean code analysis in other areas, the unescaped output represents a direct path to exploitation, and the existing vulnerability history indicates a recurring problem.
Although the plugin has a limited attack surface with only two shortcodes and no unprotected entry points, the lack of comprehensive output escaping for its 141 output instances is a major red flag. This means that a significant portion of the data displayed by the widget could be manipulated by attackers. The presence of an unpatched medium-severity XSS vulnerability in its history underscores the need for immediate attention to these escaping issues. Future development should prioritize robust output sanitization to mitigate these risks.
Key Concerns
- Unpatched CVE
- Low percentage of output escaping
- Vulnerability history of XSS
ACF Recent Posts Widget Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
ACF Recent Posts Widget <= 5.9.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
ACF Recent Posts Widget Code Analysis
Output Escaping
ACF Recent Posts Widget Attack Surface
Shortcodes 2
WordPress Hooks 19
Maintenance & Trust
ACF Recent Posts Widget Maintenance & Trust
Maintenance Signals
Community Trust
ACF Recent Posts Widget Alternatives
Recent Posts Widget With Thumbnails
recent-posts-widget-with-thumbnails
List the most recent posts with post titles, thumbnails, excerpts, authors, categories, dates and more!
Social LikeBox & Feed
facebook-by-weblizar
Display your FaceBook Feed and Like box on your website with this outstanding plugin. It is completely customizable, responsive and the code is search …
Ultimate Posts Widget
ultimate-posts-widget
The ultimate widget for displaying posts, custom post types or sticky posts with an array of options.
WP Latest Posts
wp-latest-posts
Load your content from posts, page, tags or custom post type and display it anywhere in WordPress including in Gutenberg editor
WP Tab Widget
wp-tab-widget
WP Tab Widget is the AJAXified plugin which loads content by demand, and thus it makes the plugin incredibly lightweight.
ACF Recent Posts Widget Developer Profile
1 plugin · 500 total installs
How We Detect ACF Recent Posts Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.