cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forcategory-posts category-posts

Direction: ascending
Jul 28, 2024

Category Posts Widget # CVE-2024-6158

CVE, Research URL

CVE-2024-6158

Application

Category Posts Widget

Date
Aug 12, 2024
Research Description
The Category Posts Widget WordPress plugin before 4.9.17, term-and-category-based-posts-widget WordPress plugin before 4.9.13 does not validate and escape some of its "Category Posts" widget settings before outputting them back in a page/post where the Widget is embed, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Affected versions
Min -, max -.
Status
vulnerable
Jan 08, 2025

Category Posts Widget # CVE-2024-9638

CVE, Research URL

CVE-2024-9638

Application

Category Posts Widget

Date
Jan 07, 2025
Research Description
The Category Posts Widget WordPress plugin before 4.9.18 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Affected versions
Min -, max -.
Status
vulnerable
May 07, 2025

Category Posts Widget # CVE-2025-1453

CVE, Research URL

CVE-2025-1453

Application

Category Posts Widget

Date
Apr 24, 2025
Research Description
The Category Posts Widget WordPress plugin before 4.9.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Affected versions
Min -, max -.
Status
vulnerable