BRIEFING NOTE - CVE-2026-3005 OVERVIEW The List Category Posts plugin for WordPress versions up to 0.94.0 contains a stored cross-site scripting (XSS) vulnerability in the 'catlist' shortcode. Insufficient input sanitization and output escaping of user-supplied attributes allows attackers to inject and persist malicious scripts within page content. SEVERITY This vulnerability requires network access and low privilege escalation (contributor-level or higher authentication), carrying a CVSS v3.1 base score of 6.4 (MEDIUM). The attack has no user interaction requirement but produces limited impact, compromising confidentiality and integrity while maintaining availability. The vulnerability affects all users who access pages containing injected shortcode content. EXPLOITATION STATUS The vulnerability currently shows low exploitation activity with no known public exploit code circulating. The EPSS score of 0.00032 indicates minimal real-world exploitation likelihood, and it is not listed on the CISA Known Exploited Vulnerabilities catalog. Community attention remains minimal, suggesting this poses a lower immediate threat despite the FAUCET risk score of 44.0/100.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Fernandobt | List Category Posts | >= 0, <= 0.94.0CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.