CVE-2017-18585: Ivycat Posts In Page

High severity, CVSS 8.1. EPSS: 2% chance of exploitation in the next 30 days.

The posts-in-page plugin before 1.3.0 for WordPress has ic_add_posts template='../ directory traversal.

Affected products

  • Ivycat Posts In Page: before 1.3.0 (fixed in 1.3.0)

Published 2019-08-22. Last modified 2026-06-17.