CVE-2025-28894
CVSS 3.1 Score 7.1 of 10 (high)
Details
Summary
CVE-2025-28894 is a Cross-Site Request Forgery (CSRF) vulnerability identified in the List of Posts from each Category plugin for WordPress. This issue allows an attacker to inject malicious scripts into a victim's WordPress website via a Stored XSS (Cross-Site Scripting) attack. Successful exploitation of this vulnerability could lead to unauthorized data manipulation or unintended user actions, posing a significant security risk. The vulnerability affects all versions of the List of Posts from each Category plugin from n/a through 2.0. WordPress users are advised to update to the latest version of the plugin or consider disabling it as a temporary measure until a patch is released.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.