plugin

Authors List Vulnerabilities

11 known security issues reported for the Authors List WordPress plugin. Most recent disclosed Nov 11, 2025.

1 high 4 medium

Running Authors List on your site? Check whether your installed version is affected.

Scan your site free

Authors List [authors-list] <= 2.0.6.1 (unfixed)

unknown

[en] The Authors List plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.6.1 via the via arbitrary method call from Authors_List_Shortcode class. This makes it possible for authenticated attackers, with Contributor-level access and above, to call methods such...

Affected:
up to 2.0.6.1
Fix:
No patched version reported
Disclosed:
Nov 11, 2025

CVE-2025-12010 on NVD →

Authors List <= 2.0.6.1 - Authenticated (Contributor+) Sensitive Information Exposure via Limited Method Call in Plugin's Shortcode

medium

The Authors List plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.6.1 via the via arbitrary method call from Authors_List_Shortcode class. This makes it possible for authenticated attackers, with Contributor-level access and above, to call methods such as ge...

CVSS:
6.5
Affected:
up to 2.0.6.1
Fixed in:
2.0.6.2
Disclosed:
Nov 10, 2025

CVE-2025-12010 on NVD →

Authors List <= 2.0.6.1 - Cross-Site Request Forgery

medium

The Authors List plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.6.1. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can trick a site admini...

CVSS:
4.3
Affected:
up to 2.0.6.1
Fix:
No patched version reported
Disclosed:
Sep 5, 2025

CVE-2025-58792 on NVD →

Authors List [authors-list] <= 2.0.6.1 (unfixed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in WPKube Authors List allows Cross Site Request Forgery. This issue affects Authors List: from n/a through 2.0.6.1.

Affected:
up to 2.0.6.1
Fix:
No patched version reported
Disclosed:
Sep 5, 2025

CVE-2025-58792 on NVD →

Authors List [authors-list] < 2.0.6.1

unknown

[en] The The Authors List plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.0.6. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attac...

Affected:
up to 2.0.6.1
Fixed in:
2.0.6.1
Disclosed:
Mar 1, 2025

CVE-2024-13806 on NVD →

Authors List <= 2.0.6 - Unauthenticated Arbitrary Shortcode Execution

medium

The The Authors List plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.0.6. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers...

CVSS:
6.5
Affected:
up to 2.0.6
Fixed in:
2.0.6.1
Disclosed:
Feb 28, 2025

CVE-2024-13806 on NVD →

Authors List [authors-list] < 2.0.5

unknown

[en] The The Authors List plugin for WordPress is vulnerable to arbitrary shortcode execution via update_authors_list_ajax AJAX action in all versions up to, and including, 2.0.4. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This ma...

Affected:
up to 2.0.5
Fixed in:
2.0.5
Disclosed:
Dec 4, 2024

CVE-2024-10952 on NVD →

Authors List <= 2.0.4 - Unauthenticated Arbitrary Shortcode Execution via update_authors_list_ajax

high

The The Authors List plugin for WordPress is vulnerable to arbitrary shortcode execution via update_authors_list_ajax AJAX action in all versions up to, and including, 2.0.4. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes i...

CVSS:
7.3
Affected:
up to 2.0.4
Fixed in:
2.0.5
Disclosed:
Dec 3, 2024

CVE-2024-10952 on NVD →

Authors List [authors-list] < 2.0.3

unknown

[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPKube Authors List plugin <= 2.0.2 versions.

Affected:
up to 2.0.3
Fixed in:
2.0.3
Disclosed:
Jul 27, 2023

CVE-2023-37981 on NVD →

Authors List <= 2.0.2 - Reflected Cross-Site Scripting via al_id

medium

The Authors List plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the al_id parameter in versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if...

CVSS:
6.1
Affected:
up to 2.0.3
Fixed in:
2.0.3
Disclosed:
Jul 10, 2023

CVE-2023-37981 on NVD →

Authors List [authors-list] < 2.0.3

unknown

The Authors List plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the al_id parameter in versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if...

Affected:
up to 2.0.3
Fixed in:
2.0.3
Disclosed:
Jul 10, 2023

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database