PT-2025-44703 · WordPress · List Category Posts

Athiwat Tiprasaharn

·

Published

2025-11-01

·

Updated

2025-11-19

·

CVE-2025-11377

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions WordPress List category posts plugin versions prior to 0.92.0
Description The List category posts plugin for WordPress has an information exposure issue due to insufficient restrictions on posts included by the 'catlist' shortcode. This allows authenticated attackers with contributor-level access or higher to extract data from password-protected, private, or draft posts that they should not be able to access.
Recommendations Update to a version later than 0.92.0.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-11377

Affected Products

List Category Posts