Terms and Category Based Posts Widget [term-and-category-based-posts-widget] < 4.9.13
unknown
[en] The Category Posts Widget WordPress plugin before 4.9.17, term-and-category-based-posts-widget WordPress plugin before 4.9.13 does not validate and escape some of its "Category Posts" widget settings before outputting them back in a page/post where the Widget is embed, which could allow high privilege users such a...
- Affected:
- up to 4.9.13
- Fixed in:
- 4.9.13
- Disclosed:
- Aug 9, 2024
CVE-2024-6158 on NVD →
Category Posts Widget <= 4.9.16 & Pro < 4.9.13 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Category Posts Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the excerpt_more_text field in all versions up to, and including, 4.9.16 (and versions up to 4.9.13 for PRO) due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wi...
- CVSS:
- 4.4
- Affected:
- up to 4.9.12
- Fixed in:
- 4.9.13
- Disclosed:
- Jul 19, 2024
CVE-2024-6158 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database