cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forauthors-list authors-list

Direction: descending
Dec 11, 2025

Authors List # CVE-2025-12010

CVE, Research URL

CVE-2025-12010

Application

Authors List

Date
Nov 11, 2025
Research Description
The Authors List plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.6.1 via the via arbitrary method call from Authors_List_Shortcode class. This makes it possible for authenticated attackers, with Contributor-level access and above, to call methods such as get_meta to extract sensitive user data including password hashes, email addresses, usernames, and activation keys via specially crafted shortcode attributes
Affected versions
max 2.0.6.1.
Status
vulnerable
Sep 07, 2025

Authors List # CVE-2025-58792

CVE, Research URL

CVE-2025-58792

Application

Authors List

Date
Sep 05, 2025
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in WPKube Authors List allows Cross Site Request Forgery. This issue affects Authors List: from n/a through 2.0.6.1.
Affected versions
max 2.0.6.1.
Status
vulnerable
Mar 03, 2025

Authors List # CVE-2024-13806

CVE, Research URL

CVE-2024-13806

Application

Authors List

Date
Mar 01, 2025
Research Description
The The Authors List plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.0.6. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
Affected versions
max 2.0.6.1.
Status
vulnerable
Dec 06, 2024

Authors List # CVE-2024-10952

CVE, Research URL

CVE-2024-10952

Application

Authors List

Date
Dec 04, 2024
Research Description
The The Authors List plugin for WordPress is vulnerable to arbitrary shortcode execution via update_authors_list_ajax AJAX action in all versions up to, and including, 2.0.4. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
Affected versions
max 2.0.5.
Status
vulnerable
Jun 06, 2024

Authors List # CVE-2023-37981

CVE, Research URL

CVE-2023-37981

Application

Authors List

Date
Jul 27, 2023
Research Description
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPKube Authors List plugin <= 2.0.2 versions.
Affected versions
max 2.0.3.
Status
vulnerable

Authors List # cbbd4ece10cadfe6b69d301bf453299da41ad0b8

Application

Authors List

Date
Jul 10, 2023
Research Description
Authors List [authors-list] < 2.0.3 Authors List <= 2.0.2 - Reflected Cross-Site Scripting via al_id The Authors List plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the al_id parameter in versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
max 2.0.3.
Status
vulnerable