plugin

Term And Category Based Posts Widget Vulnerabilities

2 known security issues reported for the Term And Category Based Posts Widget WordPress plugin. Most recent disclosed Aug 9, 2024.

1 medium

Running Term And Category Based Posts Widget on your site? Check whether your installed version is affected.

Scan your site free

Terms and Category Based Posts Widget [term-and-category-based-posts-widget] < 4.9.13

unknown

[en] The Category Posts Widget WordPress plugin before 4.9.17, term-and-category-based-posts-widget WordPress plugin before 4.9.13 does not validate and escape some of its "Category Posts" widget settings before outputting them back in a page/post where the Widget is embed, which could allow high privilege users such a...

Affected:
up to 4.9.13
Fixed in:
4.9.13
Disclosed:
Aug 9, 2024

CVE-2024-6158 on NVD →

Category Posts Widget <= 4.9.16 & Pro < 4.9.13 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Category Posts Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the excerpt_more_text field in all versions up to, and including, 4.9.16 (and versions up to 4.9.13 for PRO) due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wi...

CVSS:
4.4
Affected:
up to 4.9.12
Fixed in:
4.9.13
Disclosed:
Jul 19, 2024

CVE-2024-6158 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database