ZeroHour

CVE-2024-43919

moderate

Unauthenticated Access-Control Flaw in WordPress YARPP Plugin through 5.30.10

CVSS 3.1
9.8 critical
EPSS
44%p99
Published
()
Modified
AI analysis

CVE-2024-43919 is a missing-authorization (CWE-862) access-control vulnerability in YARPP (Yet Another Related Posts Plugin), a related-posts plugin for WordPress. The affected code performs privileged actions without a proper capability/authorization check, and the CVSS vector (network attack vector, no privileges required, no user interaction) indicates an unauthenticated attacker can trigger it remotely. The critical 9.8 score with high confidentiality, integrity and availability impact means successful exploitation could result in full compromise of the affected WordPress site. Any WordPress installation running YARPP in any version through 5.30.10 is affected. There is no public proof-of-concept and it is not yet in CISA KEV, but EPSS assigns a 44.5% probability of exploitation within 30 days (99th percentile), so urgent patching is warranted.

What to do: Update YARPP to the latest patched release, i.e., any version newer than 5.30.10, as the first priority; if updating is not immediately possible, deactivate the plugin until a patched version is deployed. Administrators should review access logs for unauthenticated requests targeting the plugin's endpoints and watch for a public PoC or in-the-wild exploitation given the elevated EPSS score.

Affected
yarpp Yet Another Related Posts Plugin (YARPP)all versions through 5.30.10 (including n/a through 5.30.10)
Estimated exposure
moderatetens of thousands of WordPress sites (tens of thousands of active installs for YARPP) — YARPP's WordPress.org plugin listing reports active-install counts in the tens of thousands, and only sites with the plugin active are exposed.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Access Control vulnerability in YARPP YARPP allows . This issue affects YARPP: from n/a through 5.30.10.

Vendors
yarpp
Products
yet another related posts plugin
Ecosystems
WordPress
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.