ZeroHour

Vulnerabilities

7 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-43919
Unauthenticated Access-Control Flaw in WordPress YARPP Plugin through 5.30.10

CVE-2024-43919 is a missing-authorization (CWE-862) access-control vulnerability in YARPP (Yet Another Related Posts Plugin), a related-posts plugin for WordPress. The affected code performs privileged actions without a proper capability/authorization check, and the CVSS vector (network attack vector, no privileges required, no user interaction) indicates an unauthenticated attacker can trigger it remotely. The critical 9.8 score with high confidentiality, integrity and availability impact means successful exploitation could result in full compromise of the affected WordPress site. Any WordPress installation running YARPP in any version through 5.30.10 is affected. There is no public proof-of-concept and it is not yet in CISA KEV, but EPSS assigns a 44.5% probability of exploitation within 30 days (99th percentile), so urgent patching is warranted.

Do: Update YARPP to the latest patched release, i.e., any version newer than 5.30.10, as the first priority; if updating is not immediately possible, deactivate the plugin until a patched version is deployed. Administrators should review access logs for unauthenticated requests targeting the plugin's endpoints and watch for a public PoC or in-the-wild exploitation given the elevated EPSS score.

9.844%
  • yarpp Yet Another Related Posts Plugin (YARPP) all versions through 5.30.10 (including n/a through 5.30.10)
moderatetens of thousands of WordPress sites (tens of thousands of active installs for YARPP)
CVE-2023-6495
The YARPP – Yet Another Related Posts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to and incl

The YARPP – Yet Another Related Posts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to and including 5.30.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

NVD description · AI analysis pending
4.8<1%
  • yarpp yet another related posts plugin
CVE-2022-45374
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in YARPP allows PHP Local File Inclusion.This issue affects YARPP:

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in YARPP allows PHP Local File Inclusion.This issue affects YARPP: from n/a through 5.30.4.

NVD description · AI analysis pending
6.5<1%
  • yarpp yet another related posts plugin
CVE-2024-0602
The YARPP – Yet Another Related Posts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and inc

The YARPP – Yet Another Related Posts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.30.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

NVD description · AI analysis pending
4.0<1% PoC
  • yarpp yet another related posts plugin
CVE-2023-0579
The YARPP WordPress plugin before 5.30.3 does not validate and escape some of its shortcode attributes before using them in SQL statement/s, which could allow a

The YARPP WordPress plugin before 5.30.3 does not validate and escape some of its shortcode attributes before using them in SQL statement/s, which could allow any authenticated users, such as subscribers to perform SQL Injection attacks.

NVD description · AI analysis pending
8.8<1% PoC
  • yarpp yet another related posts plugin
CVE-2023-2433
The YARPP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'className' parameter in versions up to, and including, 5.30.3 due to insufficie

The YARPP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'className' parameter in versions up to, and including, 5.30.3 due to insufficient input sanitization and output escaping. This makes it possible for contributor-level attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

NVD description · AI analysis pending
5.4<1%
  • yarpp yet another related posts plugin
CVE-2022-4471
The YARPP WordPress plugin before 5.30.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shor

The YARPP WordPress plugin before 5.30.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

NVD description · AI analysis pending
5.4<1% PoC
  • yarpp yet another related posts plugin