CVE-2025-28894

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Mar 11, 2025
CWE ID 352

Summary

CVE-2025-28894 is a Cross-Site Request Forgery (CSRF) vulnerability identified in the List of Posts from each Category plugin for WordPress. This issue allows an attacker to inject malicious scripts into a victim's WordPress website via a Stored XSS (Cross-Site Scripting) attack. Successful exploitation of this vulnerability could lead to unauthorized data manipulation or unintended user actions, posing a significant security risk. The vulnerability affects all versions of the List of Posts from each Category plugin from n/a through 2.0. WordPress users are advised to update to the latest version of the plugin or consider disabling it as a temporary measure until a patch is released.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share