plugin

St Category Wp Vulnerabilities

2 known security issues reported for the St Category Wp WordPress plugin. Most recent disclosed Oct 21, 2025.

1 medium

Running St Category Wp on your site? Check whether your installed version is affected.

Scan your site free

ST Categories Widget <= 1.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The ST Categories Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's st-categories shortcode in versions less than, or equal to, 1.0.0. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attacker...

CVSS:
6.4
Affected:
up to 1.0.0
Fix:
No patched version reported
Disclosed:
Oct 21, 2025

CVE-2025-11878 on NVD →

ST Categories Widget [st-category-wp] <= 1.0.0 (unfixed)

unknown
Affected:
up to 1.0.0
Fix:
No patched version reported

CVE-2025-11878 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database