Authors List [authors-list] <= 2.0.6.1 (unfixed)
unknown
[en] The Authors List plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.6.1 via the via arbitrary method call from Authors_List_Shortcode class. This makes it possible for authenticated attackers, with Contributor-level access and above, to call methods such...
- Affected:
- up to 2.0.6.1
- Fix:
- No patched version reported
- Disclosed:
- Nov 11, 2025
CVE-2025-12010 on NVD →
Authors List <= 2.0.6.1 - Authenticated (Contributor+) Sensitive Information Exposure via Limited Method Call in Plugin's Shortcode
medium
The Authors List plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.6.1 via the via arbitrary method call from Authors_List_Shortcode class. This makes it possible for authenticated attackers, with Contributor-level access and above, to call methods such as ge...
- CVSS:
- 6.5
- Affected:
- up to 2.0.6.1
- Fixed in:
- 2.0.6.2
- Disclosed:
- Nov 10, 2025
CVE-2025-12010 on NVD →
Authors List <= 2.0.6.1 - Cross-Site Request Forgery
medium
The Authors List plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.6.1. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can trick a site admini...
- CVSS:
- 4.3
- Affected:
- up to 2.0.6.1
- Fix:
- No patched version reported
- Disclosed:
- Sep 5, 2025
CVE-2025-58792 on NVD →
Authors List [authors-list] <= 2.0.6.1 (unfixed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in WPKube Authors List allows Cross Site Request Forgery. This issue affects Authors List: from n/a through 2.0.6.1.
- Affected:
- up to 2.0.6.1
- Fix:
- No patched version reported
- Disclosed:
- Sep 5, 2025
CVE-2025-58792 on NVD →
Authors List [authors-list] < 2.0.6.1
unknown
[en] The The Authors List plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.0.6. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attac...
- Affected:
- up to 2.0.6.1
- Fixed in:
- 2.0.6.1
- Disclosed:
- Mar 1, 2025
CVE-2024-13806 on NVD →
Authors List <= 2.0.6 - Unauthenticated Arbitrary Shortcode Execution
medium
The The Authors List plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.0.6. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers...
- CVSS:
- 6.5
- Affected:
- up to 2.0.6
- Fixed in:
- 2.0.6.1
- Disclosed:
- Feb 28, 2025
CVE-2024-13806 on NVD →
Authors List [authors-list] < 2.0.5
unknown
[en] The The Authors List plugin for WordPress is vulnerable to arbitrary shortcode execution via update_authors_list_ajax AJAX action in all versions up to, and including, 2.0.4. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This ma...
- Affected:
- up to 2.0.5
- Fixed in:
- 2.0.5
- Disclosed:
- Dec 4, 2024
CVE-2024-10952 on NVD →
Authors List <= 2.0.4 - Unauthenticated Arbitrary Shortcode Execution via update_authors_list_ajax
high
The The Authors List plugin for WordPress is vulnerable to arbitrary shortcode execution via update_authors_list_ajax AJAX action in all versions up to, and including, 2.0.4. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes i...
- CVSS:
- 7.3
- Affected:
- up to 2.0.4
- Fixed in:
- 2.0.5
- Disclosed:
- Dec 3, 2024
CVE-2024-10952 on NVD →
Authors List [authors-list] < 2.0.3
unknown
[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPKube Authors List plugin <= 2.0.2 versions.
- Affected:
- up to 2.0.3
- Fixed in:
- 2.0.3
- Disclosed:
- Jul 27, 2023
CVE-2023-37981 on NVD →
Authors List <= 2.0.2 - Reflected Cross-Site Scripting via al_id
medium
The Authors List plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the al_id parameter in versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if...
- CVSS:
- 6.1
- Affected:
- up to 2.0.3
- Fixed in:
- 2.0.3
- Disclosed:
- Jul 10, 2023
CVE-2023-37981 on NVD →
Authors List [authors-list] < 2.0.3
unknown
The Authors List plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the al_id parameter in versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if...
- Affected:
- up to 2.0.3
- Fixed in:
- 2.0.3
- Disclosed:
- Jul 10, 2023
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database