Yarpp
Yarpp YET Another Related Posts Plugin: vulnerabilidades y CVE
Yarpp YET Another Related Posts Plugin tiene 7 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-43919 | Crítica (9.8) | 45% | — | 1 nov 2024 | Access Control vulnerability in YARPP YARPP allows . This issue affects YARPP: from n/a through 5.30.10. |
| CVE-2023-6495 | Media (4.8) | 0.26% | — | 19 jun 2024 | The YARPP – Yet Another Related Posts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to and including 5.30.9 due to insufficient input sanitization and… |
| CVE-2022-45374 | Media (6.5) | 0.84% | — | 17 may 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in YARPP allows PHP Local File Inclusion.This issue affects YARPP: from n/a through 5.30.4. |
| CVE-2024-0602 | Media (4) | 0.51% | — | 29 feb 2024 | The YARPP – Yet Another Related Posts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.30.9 due to insufficient input sanitization and… |
| CVE-2023-0579 | Alta (8.8) | 0.94% | — | 16 ago 2023 | The YARPP WordPress plugin before 5.30.3 does not validate and escape some of its shortcode attributes before using them in SQL statement/s, which could allow any authenticated users, such as subscribers to perform SQL… |
| CVE-2023-2433 | Media (5.4) | 0.51% | — | 18 jul 2023 | The YARPP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'className' parameter in versions up to, and including, 5.30.3 due to insufficient input sanitization and output escaping. This makes it… |
| CVE-2022-4471 | Media (5.4) | 0.71% | — | 13 feb 2023 | The YARPP WordPress plugin before 5.30.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the… |