CVE · Medium

CVE-2024-6158 — Category Posts Widget [category-posts] < 4.9.17

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-6158 Category Posts Widget [category-posts] < 4.9.17 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 4.9.17 4.9.17 2024-07-19

CVE-2024-6158

A vulnerability exists in the Category Posts Widget plugin for WordPress due to inadequate handling of input data from the excerpt_more_text field. In versions up to 4.9.16, including this one, attackers with admin-level access can inject malicious web code that will be executed when a user visits the compromised page. This flaw only affects multi-site setups where unfiltered HTML is restricted.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.