CVE-2024-43919
moderateUnauthenticated Access-Control Flaw in WordPress YARPP Plugin through 5.30.10
CVE-2024-43919 is a missing-authorization (CWE-862) access-control vulnerability in YARPP (Yet Another Related Posts Plugin), a related-posts plugin for WordPress. The affected code performs privileged actions without a proper capability/authorization check, and the CVSS vector (network attack vector, no privileges required, no user interaction) indicates an unauthenticated attacker can trigger it remotely. The critical 9.8 score with high confidentiality, integrity and availability impact means successful exploitation could result in full compromise of the affected WordPress site. Any WordPress installation running YARPP in any version through 5.30.10 is affected. There is no public proof-of-concept and it is not yet in CISA KEV, but EPSS assigns a 44.5% probability of exploitation within 30 days (99th percentile), so urgent patching is warranted.
What to do: Update YARPP to the latest patched release, i.e., any version newer than 5.30.10, as the first priority; if updating is not immediately possible, deactivate the plugin until a patched version is deployed. Administrators should review access logs for unauthenticated requests targeting the plugin's endpoints and watch for a public PoC or in-the-wild exploitation given the elevated EPSS score.
| yarpp Yet Another Related Posts Plugin (YARPP) | all versions through 5.30.10 (including n/a through 5.30.10) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Access Control vulnerability in YARPP YARPP allows . This issue affects YARPP: from n/a through 5.30.10.
- Vendors
- yarpp
- Products
- yet another related posts plugin
- Ecosystems
- WordPress
- Weakness
- CWE-862
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.