CVE-2025-47636
WordPress List category posts plugin <= 0.91.0 - Local File Inclusion Vulnerability
CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th
Path Traversal: '.../...//' vulnerability in Fernando Briano List category posts list-category-posts allows PHP Local File Inclusion.This issue affects List category posts: from n/a through <= 0.91.0.
| CWE | CWE-35 |
| Vendor | fernando briano |
| Product | list category posts |
| Published | May 7, 2025 |
| Last Updated | Apr 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for fernando briano list category posts
Be the first to know when new high vulnerabilities affecting fernando briano list category posts are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
Fernando Briano / List category posts
0 ≤ 0.91.0
References
Credits
Trương Hữu Phúc (truonghuuphuc) | Patchstack Bug Bounty Program