CVE-2024-9020

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-9020
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-9020.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-9020
Published
2025-01-18T06:15:27Z
Modified
2025-05-17T14:23:59.840862Z
Summary
[none]
Details

The List category posts WordPress plugin before 0.90.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

References

Affected packages

Git / github.com/picandocodigo/list-category-posts

Affected ranges

Type
GIT
Repo
https://github.com/picandocodigo/list-category-posts
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

0.*

0.65
0.66
0.67
0.68
0.72
0.75
0.85.1

v0.*

v0.36-pagination-alpha.1
v0.38-alpha
v0.46.4
v0.77
v0.78
v0.79
v0.80.1
v0.80.2
v0.81
v0.82
v0.83
v0.83.1
v0.84
v0.84.1
v0.84.2
v0.85
v0.86
v0.86.1
v0.87
v0.88
v0.88.1
v0.89
v0.89.1
v0.89.2
v0.89.3
v0.89.4
v0.89.5
v0.89.6
v0.89.7
v0.89.8
v0.89.9
v0.90.0
v0.90.1
v0.90.2