← WordPress Vulnerabilities
WordPress security by component

Categorify

Categorify is a WordPress component with 11 published CVE records in this archive. The latest tracked vulnerability was published Sep 09, 2025; the highest CVE/CNA score is 4.3.

Plugin slug: categorify

CVE-2025-59005: Categorify: A security weakness

Categorify is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.

PublishedSep 09, 2025
Safe version guidanceSee mitigation notes
Safe version
Sep 09, 2025 CVE-2025-59005
Categorify: A security weakness
Categorify is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Mar 13, 2024 CVE-2024-0385
Categorify: A security weakness
Categorify is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Feb 27, 2024 CVE-2024-1912
Categorify: Cross-site request forgery
Categorify is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Feb 27, 2024 CVE-2024-1910
Categorify: Cross-site request forgery
Categorify is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Feb 27, 2024 CVE-2024-1909
Categorify: Cross-site request forgery
Categorify is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Feb 27, 2024 CVE-2024-1907
Categorify: Cross-site request forgery
Categorify is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Feb 27, 2024 CVE-2024-1906
Categorify: Cross-site request forgery
Categorify is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Feb 27, 2024 CVE-2024-1653
Categorify: A security weakness
Categorify is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Feb 27, 2024 CVE-2024-1652
Categorify: A security weakness
Categorify is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Feb 27, 2024 CVE-2024-1650
Categorify: A security weakness
Categorify is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Feb 27, 2024 CVE-2024-1649
Categorify: A security weakness
Categorify is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending