Known Vulnerabilities for products from W4 Post List Project
Listed below are 4 of the newest known vulnerabilities associated with the vendor "W4 Post List Project".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-42461 json | Not Provided | 2026-05-09 | 2026-05-13 | |
| CVE-2023-27413 json | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Shazzad Hossain Khan W4 Post List plugin <= 2.4.4 ve... | 5.4 - MEDIUM | 2023-06-22 | 2023-06-28 |
| CVE-2023-1373 json | The W4 Post List WordPress plugin before 2.4.6 does not escape some URLs before outputting them in attributes, leading to Ref... | 6.1 - MEDIUM | 2023-04-17 | 2023-11-07 |
| CVE-2023-1371 json | The W4 Post List WordPress plugin before 2.4.6 does not ensure that password protected posts can be accessed before displayin... | 6.5 - MEDIUM | 2023-04-17 | 2023-11-07 |
| CVE-2023-0374 json | The W4 Post List WordPress plugin before 2.4.6 does not validate and escape some of its block options before outputting them ... | 5.4 - MEDIUM | 2023-04-17 | 2023-11-07 |