CVE · Medium

CVE-2026-12434 — List category posts [list-category-posts] < 0.96.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-12434 List category posts [list-category-posts] < 0.96.0 Missing Authorization Medium 4.3 < 0.96.0 0.96.0 2026-07-15

CVE-2026-12434

A security flaw exists within the List category posts plugin, affecting all versions prior to 0.95.0. The sanitize_status function allows users with contributor-level access or higher to extract metadata from other users' unpublished and deleted posts by inserting a specially crafted shortcode into their own draft. This vulnerability exploits an incomplete fix for a previous issue in version 0.93.0.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.