CVE Database /
CVE-2026-12434
CVE · Medium
CVE-2026-12434 — List category posts [list-category-posts] < 0.96.0
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-12434
|
List category posts [list-category-posts] < 0.96.0 |
Missing Authorization |
Medium
4.3
|
< 0.96.0
|
0.96.0 |
2026-07-15 |
—
|
CVE-2026-12434
A security flaw exists within the List category posts plugin, affecting all versions prior to 0.95.0. The sanitize_status function allows users with contributor-level access or higher to extract metadata from other users' unpublished and deleted posts by inserting a specially crafted shortcode into their own draft. This vulnerability exploits an incomplete fix for a previous issue in version 0.93.0.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings