CVE-2024-43919
- EPSS 84.84%
- Veröffentlicht 01.11.2024 15:15:48
- Zuletzt bearbeitet 13.11.2024 15:02:22
Access Control vulnerability in YARPP YARPP allows . This issue affects YARPP: from n/a through 5.30.10.
CVE-2023-6495
- EPSS 0.19%
- Veröffentlicht 19.06.2024 09:15:10
- Zuletzt bearbeitet 08.04.2026 19:18:55
The YARPP – Yet Another Related Posts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to and including 5.30.9 due to insufficient input sanitization and output escaping. This makes it pos...
CVE-2022-45374
- EPSS 0.96%
- Veröffentlicht 17.05.2024 07:15:47
- Zuletzt bearbeitet 05.03.2025 18:25:53
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in YARPP allows PHP Local File Inclusion.This issue affects YARPP: from n/a through 5.30.4.
- EPSS 0.19%
- Veröffentlicht 29.02.2024 01:43:22
- Zuletzt bearbeitet 08.04.2026 17:17:23
The YARPP – Yet Another Related Posts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.30.9 due to insufficient input sanitization and output escaping. This makes it p...
CVE-2023-0579
- EPSS 0.28%
- Veröffentlicht 16.08.2023 12:15:12
- Zuletzt bearbeitet 24.03.2026 19:02:38
The YARPP WordPress plugin before 5.30.3 does not validate and escape some of its shortcode attributes before using them in SQL statement/s, which could allow any authenticated users, such as subscribers to perform SQL Injection attacks.
CVE-2023-2433
- EPSS 0.15%
- Veröffentlicht 18.07.2023 09:15:11
- Zuletzt bearbeitet 08.04.2026 18:18:01
The YARPP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'className' parameter in versions up to, and including, 5.30.3 due to insufficient input sanitization and output escaping. This makes it possible for contributor-level at...
CVE-2022-4471
- EPSS 0.69%
- Veröffentlicht 13.02.2023 15:15:16
- Zuletzt bearbeitet 21.03.2025 20:15:13
The YARPP WordPress plugin before 5.30.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Sto...