N/A
2026-04-08< 0.95.0
List category posts <= 0.94.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'catlist' Shortcode
Minimum safe version
0.95.0
Update to 0.95.0 or later to address 8 fixable vulnerabilities
List category posts <= 0.94.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'catlist' Shortcode
CVE-2026-32419
CVE-2025-10163
CVE-2025-11377
CVE-2025-47636
WordPress List category posts Plugin < 0.90.3 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-1051
CVE-2023-6994