PLUGIN SECURITY
Is List Category Posts safe?
Very customizable plugin to list posts by category (or tag, author and more) in a post, page or widget. Uses the [catlist] shortcode to select posts.
What this plugin does
- Slug:
list-category-posts - Author: Fernando Briano
- 80000+ active installs
- 94/100 rating (254 reviews on wordpress.org)
- 4439154 all-time downloads
- On WordPress.org since 2008-08-16
categoriescmslistposts
Maintenance status
- Latest known version: 0.96.0
- Last updated: 2026-07-07 7:28am GMT
- Tested up to WordPress: 7.0.4
- Requires PHP: 5.6+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
9 known CVEs on file for List Category Posts.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-12434 | List category posts [list-category-posts] < 0.96.0 | Missing Authorization | Medium 4.3 | < 0.96.0 | 0.96.0 | 2026-07-15 | ✓ fixed in latest |
| CVE-2026-32419 | List category posts [list-category-posts] < 0.94.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.9 | < 0.94.0 | 0.94.0 | 2026-02-26 | ✓ fixed in latest |
| CVE-2025-10163 | List category posts [list-category-posts] < 0.92.0 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | Medium 6.5 | < 0.92.0 | 0.92.0 | 2025-12-10 | ✓ fixed in latest |
| CVE-2025-11377 | List category posts [list-category-posts] < 0.93.0 | Exposure of Sensitive Information to an Unauthorized Actor | Medium 4.3 | < 0.93.0 | 0.93.0 | 2025-10-31 | ✓ fixed in latest |
| CVE-2025-47636 | List category posts [list-category-posts] < 0.92.0 | Path Traversal: '.../...//' | High 7.5 | < 0.92.0 | 0.92.0 | 2025-05-07 | ✓ fixed in latest |
| CVE-2024-1051 | List category posts [list-category-posts] < 0.89.7 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 0.89.7 | 0.89.7 | 2024-03-29 | ✓ fixed in latest |
| CVE-2023-6994 | List category posts [list-category-posts] < 0.89.4 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 0.89.4 | 0.89.4 | 2024-01-09 | ✓ fixed in latest |
| — | List category posts [list-category-posts] < 0.90.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 0.90.3 | 0.90.3 | 0000-00-00 | ✓ fixed in latest |
+ 3 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| — | List category posts [list-category-posts] < 0.95.0 | — | Unknown | < 0.95.0 | 0.95.0 | 0000-00-00 | ✓ fixed in latest |
| CVE-2024-9020 | List category posts < 0.90.3 - Author+ Stored XSS | — | Unknown | < 0.90.3 | 0.90.3 | — | ✓ fixed in latest |
| CVE-2026-3005 | List category posts < 0.95.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'catlist' Shortcode | — | Unknown | < 0.95.0 | 0.95.0 | — | ✓ fixed in latest |
How to fix it
Keep List Category Posts updated — 0.96.0 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- White Label CMS — 200000+ active installs — 94/100 (113) — max PHP 8.4
- Media Library Assistant — 70000+ active installs — 96/100 (201) — max PHP 8.4
- Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms — 40000+ active installs — 92/100 (194) — max PHP 8.4
- Category Posts Block — 40000+ active installs — 90/100 (79) — max PHP 8.4
- Cornerstone — 30000+ active installs — 80/100 (6) — max PHP <8.0
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.