Category Posts Widget <= 4.9.19 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Category Posts Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.9.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to i...
- CVSS:
- 4.4
- Affected:
- up to 4.9.19
- Fixed in:
- 4.9.20
- Disclosed:
- Apr 3, 2025
CVE-2025-1453 on NVD →
Category Posts Widget <= 4.9.17 - Authenticated (Admin+) Stored Cross-Site SCripting
medium
The Category Posts Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.9.17 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to i...
- CVSS:
- 4.4
- Affected:
- up to 4.9.17
- Fixed in:
- 4.9.18
- Disclosed:
- Dec 17, 2024
CVE-2024-9638 on NVD →
Category Posts Widget [category-posts] < 4.9.17
unknown
[en] The Category Posts Widget WordPress plugin before 4.9.17, term-and-category-based-posts-widget WordPress plugin before 4.9.13 does not validate and escape some of its "Category Posts" widget settings before outputting them back in a page/post where the Widget is embed, which could allow high privilege users such a...
- Affected:
- up to 4.9.17
- Fixed in:
- 4.9.17
- Disclosed:
- Aug 9, 2024
CVE-2024-6158 on NVD →
Category Posts Widget <= 4.9.16 & Pro < 4.9.13 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Category Posts Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the excerpt_more_text field in all versions up to, and including, 4.9.16 (and versions up to 4.9.13 for PRO) due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wi...
- CVSS:
- 4.4
- Affected:
- up to 4.9.16
- Fixed in:
- 4.9.17
- Disclosed:
- Jul 19, 2024
CVE-2024-6158 on NVD →
Category Posts Widget [category-posts] < 4.9.18
unknown
- Affected:
- up to 4.9.18
- Fixed in:
- 4.9.18
CVE-2024-9638 on NVD →
Category Posts Widget [category-posts] < 4.9.20
unknown
- Affected:
- up to 4.9.20
- Fixed in:
- 4.9.20
CVE-2025-1453 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database