Cross-Site Request Forgery (CSRF) vulnerability in frucomerci List of Posts from each Category plugin for WordPress allows Stored XSS. This issue affects List of Posts from each Category plugin for WordPress: from n/a through 2.0.
CVE ID: CVE-2025-28894
CVSS Base Severity: HIGH
CVSS Base Score: 7.1
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Vendor: frucomerci
Product: List of Posts from each Category plugin for WordPress
EPSS Score: 0.02% (probability of being exploited)
EPSS Percentile: 1.83% (scored less or equal to compared to others)
EPSS Date: 2025-04-09 (when was this score calculated)