๐Ÿ” CVE Alert

CVE-2025-5811

MEDIUM 5.3

Listly: Listicles For WordPress <= 2.7 - Unauthenticated Arbitrary Transient Deletion

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

The Listly: Listicles For WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Init() function in all versions up to, and including, 2.7. This makes it possible for unauthenticated attackers to delete arbitrary transient values on the WordPress site.

CWE CWE-862
Vendor milanmk
Product listly: listicles for wordpress
Published Jul 18, 2025
Last Updated Apr 8, 2026
Stay Ahead of the Next One

Get instant alerts for milanmk listly: listicles for wordpress

Be the first to know when new medium vulnerabilities affecting milanmk listly: listicles for wordpress are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

milanmk / Listly: Listicles For WordPress
0 โ‰ค 2.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/ee6749f5-1dd0-4687-9a86-64fd1161321b?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/listly/trunk/listly.php#L151 wordpress.org: https://wordpress.org/plugins/listly/

Credits

ch4r0n