CVE Database /
CVE-2024-6158
CVE · Medium
CVE-2024-6158 — Category Posts Widget [category-posts] < 4.9.17
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-6158
|
Category Posts Widget [category-posts] < 4.9.17 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
4.8
|
< 4.9.17
|
4.9.17 |
2024-07-19 |
—
|
CVE-2024-6158
A vulnerability exists in the Category Posts Widget plugin for WordPress due to inadequate handling of input data from the excerpt_more_text field. In versions up to 4.9.16, including this one, attackers with admin-level access can inject malicious web code that will be executed when a user visits the compromised page. This flaw only affects multi-site setups where unfiltered HTML is restricted.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings