CVE · High

CVE-2025-47636 — List category posts [list-category-posts] < 0.92.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-47636 List category posts [list-category-posts] < 0.92.0 Path Traversal: '.../...//' High 7.5 < 0.92.0 0.92.0 2025-05-07

CVE-2025-47636

Authenticated users with contributor-level access or higher in WordPress installations running List category posts plugin versions 0.90.3 or earlier can exploit a vulnerability allowing them to include arbitrary files on the server, enabling the execution of any PHP code within those files. This flaw enables attackers to circumvent security restrictions and potentially extract sensitive information or execute malicious code by uploading and including certain types of files that are typically considered safe.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.