CVE-2025-47636
Authenticated users with contributor-level access or higher in WordPress installations running List category posts plugin versions 0.90.3 or earlier can exploit a vulnerability allowing them to include arbitrary files on the server, enabling the execution of any PHP code within those files. This flaw enables attackers to circumvent security restrictions and potentially extract sensitive information or execute malicious code by uploading and including certain types of files that are typically considered safe.
Based on public CVE data (MITRE/NVD).