Impact
The List category posts plugin for WordPress contains a flaw that allows authenticated users with contributor-level access or higher to retrieve metadata from other users' posts. An attacker can embed a crafted [catlist] shortcode in a draft, preview it, and read titles, full content, excerpts, dates, authors, and custom field metadata of posts that are pending review, scheduled, or trashed. The vulnerability is a bypass of a prior incomplete patch and extends the scope of information exposure to all vulnerable plugin versions.
Affected Systems
This issue affects the List category posts plugin developed by fernandobt. All released versions up to and including 0.95.0 are impacted.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate risk, while the EPSS score is below 1%, suggesting a low current exploitation probability. The vulnerability is not yet listed in the CISA KEV catalog. Attackers with contributor or higher privilege can simply insert the malicious shortcode and preview it to access sensitive content, making the exploitation achievable via normal WordPress preview functionality, bypassing the incomplete fix applied in version 0.93.0.
OpenCVE Enrichment