cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forlist-category-posts list-category-posts

Direction: ascending
Jun 07, 2024

List category posts # CVE-2024-1051

CVE, Research URL

CVE-2024-1051

Application

List category posts

Date
Mar 30, 2024
Research Description
The List category posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'catlist' shortcode in all versions up to, and including, 0.89.6 due to insufficient input sanitization and output escaping on user supplied attributes like 'title_tag'. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
Min -, max -.
Status
vulnerable

List category posts # CVE-2023-6994

CVE, Research URL

CVE-2023-6994

Application

List category posts

Date
Jan 11, 2024
Research Description
The List category posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'catlist' shortcode in all versions up to, and including, 0.89.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
Min -, max -.
Status
vulnerable
Jan 21, 2025

List category posts # CVE-2024-9020

CVE, Research URL

CVE-2024-9020

Application

List category posts

Date
Jan 18, 2025
Research Description
The List category posts WordPress plugin before 0.90.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Affected versions
Min -, max -.
Status
vulnerable