Description
The List category posts plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 0.95.0 via the sanitize_status. This makes it possible for authenticated attackers, with contributor-level access and above, to extract titles, full content, excerpts, dates, authors, and custom-field metadata of other users' pending-review, scheduled, and trashed posts by embedding a crafted [catlist] shortcode in their own draft and previewing it. This vulnerability is a bypass of the incomplete fix introduced for CVE-2025-11377 in version 0.93.0.
Published: 2026-07-16
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The List category posts plugin for WordPress contains a flaw that allows authenticated users with contributor-level access or higher to retrieve metadata from other users' posts. An attacker can embed a crafted [catlist] shortcode in a draft, preview it, and read titles, full content, excerpts, dates, authors, and custom field metadata of posts that are pending review, scheduled, or trashed. The vulnerability is a bypass of a prior incomplete patch and extends the scope of information exposure to all vulnerable plugin versions.

Affected Systems

This issue affects the List category posts plugin developed by fernandobt. All released versions up to and including 0.95.0 are impacted.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate risk, while the EPSS score is below 1%, suggesting a low current exploitation probability. The vulnerability is not yet listed in the CISA KEV catalog. Attackers with contributor or higher privilege can simply insert the malicious shortcode and preview it to access sensitive content, making the exploitation achievable via normal WordPress preview functionality, bypassing the incomplete fix applied in version 0.93.0.

Generated by OpenCVE AI on July 31, 2026 at 02:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the List category posts plugin to the latest fixed version or uninstall it if no fix is available.
  • Limit contributor‑level permissions or remove the preview capability for that role to prevent access to the shortcode functionality.
  • Disable or restrict the [catlist] shortcode for non‑administrator users until the plugin is updated.

Generated by OpenCVE AI on July 31, 2026 at 02:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 16 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Description The List category posts plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 0.95.0 via the sanitize_status. This makes it possible for authenticated attackers, with contributor-level access and above, to extract titles, full content, excerpts, dates, authors, and custom-field metadata of other users' pending-review, scheduled, and trashed posts by embedding a crafted [catlist] shortcode in their own draft and previewing it. This vulnerability is a bypass of the incomplete fix introduced for CVE-2025-11377 in version 0.93.0.
Title List category posts <= 0.95.0 - Missing Authorization to Authenticated (Contributor+) Sensitive Information Exposure via 'post_status' Shortcode Attribute
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-07-16T13:39:32.157Z

Reserved: 2026-06-16T18:24:03.282Z

Link: CVE-2026-12434

cve-icon Vulnrichment

Updated: 2026-07-16T13:39:28.836Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T02:30:05Z

Weaknesses