CVE-2025-15477 | Bucketlister Plugin up to 0.1.5 on WordPress Shortcode category/id sql injection (EUVD-2025-206892)
A vulnerability marked as critical has been reported in Bucketlister Plugin up to 0.1.5 on WordPress. Impacted is an unknown function of the component Shortcode Handler. The manipulation of the argument category/id leads to sql injection.
This vulnerability is traded as CVE-2025-15477. It is possible to initiate the attack remotely. There is no exploit available.