Cision Block Security & Risk Analysis

wordpress.org/plugins/cision-block

This plugin adds a shortcode and a widget that can be used for pulling and displaying press releases from Cision.

70 active installs v4.4.0 PHP 7.4+ WP 5.3+ Updated May 5, 2025
cisionfeedirpressstock
91
A · Safe
CVEs total1
Unpatched0
Last CVEMay 5, 2025
Download
Safety Verdict

Is Cision Block Safe to Use in 2026?

Generally Safe

Score 91/100

Cision Block has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: May 5, 2025Updated 1yr ago
Risk Assessment

The "cision-block" v4.4.0 plugin presents a mixed security posture. While the static analysis indicates a relatively small attack surface with no immediately apparent unprotected entry points and a decent number of nonce and capability checks, there are significant concerns regarding code quality and historical vulnerability patterns. The presence of a `unserialize` function is a major red flag, as it can be exploited for remote code execution if not handled with extreme care and robust input validation. Coupled with this is the alarming statistic that 100% of SQL queries are not using prepared statements, increasing the risk of SQL injection vulnerabilities. The vulnerability history, despite having no currently unpatched CVEs, shows a past medium-severity Cross-site Scripting vulnerability. This pattern, combined with the poor handling of SQL and the presence of `unserialize`, suggests a tendency towards insecure coding practices. While the absence of external HTTP requests and the fact that the latest vulnerability is in the past are positives, the core code quality issues and the historical context demand caution.

Key Concerns

  • Unserialize function used
  • SQL queries not using prepared statements
  • Low percentage of output properly escaped
  • Medium severity vulnerability in history
Vulnerabilities
1 published

Cision Block Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-3782medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Cision Block <= 4.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter

May 5, 2025 Patched in 4.4.0 (1d)
Version History

Cision Block Release Timeline

v4.4.0Current
v4.3.01 CVE
v4.2.01 CVE
v4.1.01 CVE
Code Analysis
Analyzed Mar 16, 2026

Cision Block Code Analysis

Dangerous Functions
1
Raw SQL Queries
1
0 prepared
Unescaped Output
72
29 escaped
Nonce Checks
2
Capability Checks
3
File Operations
14
External Requests
0
Bundled Libraries
1

Dangerous Functions Found

unserialize$serializable = unserialize($signature['serializable']);src\Vendor\laravel\serializable-closure\src\Serializers\Signed.php:87

Bundled Libraries

Guzzle

SQL Query Safety

0% prepared1 total queries

Output Escaping

29% escaped101 total outputs
Attack Surface

Cision Block Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 1

authwp_ajax_cision_block_dismiss_noticesrc\Backend\Backend.php:103

Shortcodes 1

[cision-block] src\Frontend\Frontend.php:41
WordPress Hooks 18
actioninitbootstrap.php:38
actionadmin_menusrc\Backend\Backend.php:96
actionin_admin_headersrc\Backend\Backend.php:97
actionadmin_post_cision_block_save_settingssrc\Backend\Backend.php:98
actionadmin_enqueue_scriptssrc\Backend\Backend.php:101
actioncision_block_admin_noticessrc\Backend\Backend.php:102
filterplugin_action_linkssrc\Backend\Backend.php:111
filterplugin_row_metasrc\Backend\Backend.php:112
filtertemplate_includesrc\Frontend\Frontend.php:130
actioninitsrc\Frontend\Frontend.php:164
actionwp_enqueue_scriptssrc\Frontend\Frontend.php:165
actionpost_updatedsrc\Frontend\Frontend.php:166
actiontemplate_redirectsrc\Frontend\Frontend.php:167
actionafter_setup_themesrc\Frontend\Frontend.php:168
filterquery_varssrc\Frontend\Frontend.php:176
filterpre_get_document_titlesrc\Frontend\Frontend.php:177
filterthe_seo_framework_title_from_custom_fieldsrc\Frontend\Frontend.php:180
actionwidgets_initsrc\Plugin\Widget\Widget.php:40
Maintenance & Trust

Cision Block Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 5, 2025
PHP min version7.4
Downloads12K

Community Trust

Rating100/100
Number of ratings15
Active installs70
Developer Profile

Cision Block Developer Profile

cyclonecode

5 plugins · 10K total installs

94
trust score
Avg Security Score
92/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect Cision Block

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cision-block/build/admin.css/wp-content/plugins/cision-block/build/admin.js/wp-content/plugins/cision-block/build/frontend.css/wp-content/plugins/cision-block/build/frontend.js
Script Paths
/wp-content/plugins/cision-block/build/admin.js/wp-content/plugins/cision-block/build/frontend.js
Version Parameters
cision-block/build/admin.css?ver=cision-block/build/admin.js?ver=cision-block/build/frontend.css?ver=cision-block/build/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
cision-block-notice
Data Attributes
data-block-id
JS Globals
cb_get_container
FAQ

Frequently Asked Questions about Cision Block