N/A
2026-03-06< 6.2.0
JS Archive List <= 6.1.7 - Authenticated (Contributor+) PHP Object Injection via 'included' Shortcode Attribute
Minimum safe version
6.2.0
Update to 6.2.0 or later to address 4 fixable vulnerabilities
JS Archive List <= 6.1.7 - Authenticated (Contributor+) PHP Object Injection via 'included' Shortcode Attribute
CVE-2026-32513
WordPress JS Archive List Plugin < 6.1.6 is vulnerable to SQL Injection
JS Archive List <= 6.1.5 - Unauthenticated SQL Injection via build_sql_where Function