CVE · Medium

CVE-2025-10163 — List category posts [list-category-posts] < 0.92.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-10163 List category posts [list-category-posts] < 0.92.0 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Medium 6.5 < 0.92.0 0.92.0 2025-12-10

CVE-2025-10163

A WordPress plugin called List category posts is susceptible to a specific type of attack due to inadequate handling of user input in its shortcode functionality. The 'starting_with' parameter within the catlist shortcode fails to properly sanitize user-supplied data, allowing malicious users with at least Contributor-level access to inject additional SQL queries into existing database queries. This vulnerability can be exploited to extract sensitive information from the database.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.