Listly WordPress Plugin Transient Deletion Vulnerability

Vulnerability

A vulnerability exists in the Listly: Listicles For WordPress plugin, specifically in versions through 2.7. The issue arises from a lack of proper capability checks in the Init() function, allowing unauthenticated attackers to delete arbitrary transient values from the WordPress site.

Impact

Exploitation of this vulnerability allows for unauthorized deletion of transient data, which could disrupt normal site operations or functionality that relies on this cached data.

Reproduction

The vulnerability can be reproduced by sending a request to the WordPress site with the 'ListlyDeleteCache' parameter. This can be done through the admin interface or by using a tool that allows for the manipulation of request parameters, such as a browser extension or a script.

Remediation

There is no known patch available for this vulnerability. It is recommended to review the vulnerability details and consider uninstalling the affected plugin.

Added: Jul 18, 2025, 7:25 AM
Updated: Jul 18, 2025, 7:25 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
8.4
remediation
0.0
relevance
0.3
threat
4.8
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.