PT-2025-50571 · WordPress · Wordpress List Category Posts

Khanh Nguyen

·

Published

2025-12-11

·

Updated

2025-12-11

·

CVE-2025-10163

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions WordPress List Category Posts plugin versions through 0.91.0
Description The List category posts plugin for WordPress has a flaw where a time-based SQL Injection can occur through the starting with parameter of the catlist shortcode. This is due to inadequate escaping of user-provided input and insufficient preparation of the SQL query. Attackers with Contributor-level access or higher can add SQL queries to existing ones, potentially extracting sensitive information from the database.
Recommendations Update the WordPress List Category Posts plugin to a version later than 0.91.0.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-10163

Affected Products

Wordpress List Category Posts