{"error":0,"message":null,"data":{"name":"YARPP &#8211; Yet Another Related Posts Plugin","plugin":"yet-another-related-posts-plugin","link":"https:\/\/wordpress.org\/plugins\/yet-another-related-posts-plugin\/","latest":"1731348960","closed":1,"closed_reason":"unknown","closed_date":null,"vulnerability":[{"uuid":"b1f09ef37074888ea812acea35a2bae254411c4f81cad7b8bf45f764f2198fc9","name":"YARPP &#8211; Yet Another Related Posts Plugin [yet-another-related-posts-plugin] < 4.2.5 (closed)","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.2.5","max_operator":"lt","unfixed":"0","closed":"1"},"source":[{"id":"8355608a0a6abb435f35ab31d7b2dd3177896f21","name":"WordPress Yet Another Related Posts Plugin <= 4.2.4 - CSRF","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/yet-another-related-posts\/vulnerability\/wordpress-yet-another-related-posts-plugin-4-2-4-csrf","description":"WordPress Yet Another Related Posts plugin is prone to a cross-site request forgery vulnerability. It allows an attacker to gain unauthorized access to the affected application by performing certain actions in the context of an authorized user's session.\nUpgrade the plugin.","date":"2015-05-08"}],"impact":[]},{"uuid":"ac007309c65e88c0823232af1f4dccedbce20e9396413af7a93925574a980b52","name":"YARPP &#8211; Yet Another Related Posts Plugin [yet-another-related-posts-plugin] < 4.2.5 (closed)","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.2.5","max_operator":"lt","unfixed":"0","closed":"1"},"source":[{"id":"2cae744c-cb0e-4757-8a4d-1e18d6074f0b","name":"Yet Another Related Posts Plugin (YARPP) 4.2.4 - CSRF \/ XSS \/ RCE","link":"https:\/\/wpscan.com\/vulnerability\/2cae744c-cb0e-4757-8a4d-1e18d6074f0b","description":"&#039;Yet Another Related Posts Plugin&#039; options can be updated with no token\/nonce protection which an attacker may exploit via tricking website&#039;s administrator to enter a malformed page which will change YARPP options, and since some options allow html the attacker is able to inject malformed javascript code which can lead to code execution\/administrator actions when the injected code is triggered by an admin user.","date":null}],"impact":[]},{"uuid":"740ab8e46109afe05195d58695e3af91963d914773e4fa4ef2dd7ef0c5fe292d","name":"YARPP &#8211; Yet Another Related Posts Plugin [yet-another-related-posts-plugin] < 4.2.5 (closed)","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.2.5","max_operator":"lt","unfixed":"0","closed":"1"},"source":[{"id":"e66a513eecf438ef8b95a68c8c0e75d950757ef4","name":"YARPP \u2013 Yet Another Related Posts Plugin < 4.2.5 - Cross-Site Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/yet-another-related-posts-plugin\/yarpp-yet-another-related-posts-plugin-425-cross-site-request-forgery","description":"The YARPP \u2013 Yet Another Related Posts Plugin for WordPress is vulnerable a Cross-Site Request Forgery which can lead to Remote Code Execution in versions up to, and including, 4.2.4 via the yarpp_options.php file. This allows unauthenticated attackers to execute code on the server if they can successfully trick an administrator into performing an action such as clicking on a link.","date":"2015-05-08"}],"impact":[]},{"uuid":"2bb210d7dbb88db2629f490fc0512b23630418881fee37dedaeebfefd1d4811b","name":"YARPP &#8211; Yet Another Related Posts Plugin [yet-another-related-posts-plugin] < 5.30.3 (closed)","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.30.3","max_operator":"lt","unfixed":"0","closed":"1"},"source":[{"id":"CVE-2022-4471","name":"CVE-2022-4471","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-4471","description":"[en] The YARPP WordPress plugin before 5.30.3 does not validate and escape some of its shortcode attributes before outputting them back in a page\/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks","date":"2023-02-13"},{"id":"2d33385ca22b6e716c0d14f4b3d90697c69f2371","name":"WordPress  YARPP Plugin  <= 5.30.1 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/yet-another-related-posts-plugin\/vulnerability\/wordpress-yarpp-yet-another-related-posts-plugin-5-30-1-contributor-stored-xss-vulnerability","description":"No patched version available.\nLana Codes discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress YARPP Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has not been known to be fixed yet.","date":"2023-01-19"},{"id":"786cbe59a383e46537e559d683260f1657ed51ff","name":"YARPP \u2013 Yet Another Related Posts Plugin <= 5.30.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/yet-another-related-posts-plugin\/yarpp-yet-another-related-posts-plugin-5301-authenticated-contributor-stored-cross-site-scripting-via-shortcode","description":"The YARPP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 5.30.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NOTE: It was found that an additional shortcode attribute (template) was vulnerable in versions <= 5.30.2. This was addressed in version 5.30.3.","date":"2023-01-19"},{"id":"c6cf792b-054c-4d77-bcae-3b700f42130b","name":"YARPP - Yet Another Related Posts Plugin &lt; 5.30.3 - Contributor+ Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/c6cf792b-054c-4d77-bcae-3b700f42130b","description":"The plugin does not validate and escape some of its shortcode attributes before outputting them back in a page\/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"2574467bed210b373001efa8b5bb348d650c69cd801165796fbe2d9b99fc2083","name":"YARPP &#8211; Yet Another Related Posts Plugin [yet-another-related-posts-plugin] < 5.30.5 (closed)","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.30.5","max_operator":"lt","unfixed":"0","closed":"1"},"source":[{"id":"CVE-2022-45374","name":"CVE-2022-45374","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-45374","description":"[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in YARPP allows PHP Local File Inclusion.This issue affects YARPP: from n\/a through 5.30.4.","date":"2024-05-17"},{"id":"4e450e38bf11c97057ed352a52f244207d1bcdb1","name":"WordPress  YARPP Plugin  <= 5.30.2 is vulnerable to Local File Inclusion","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/yet-another-related-posts-plugin\/vulnerability\/wordpress-yet-another-related-posts-plugin-yarpp-plugin-5-30-2-local-file-inclusion","description":"No patched version is available. No reply from the vendor.\nRafie Muhammad (Patchstack) discovered and reported this Local File Inclusion vulnerability in WordPress YARPP Plugin. This could allow a malicious actor to include local files of the target website and show its output onto the screen. Files which store credentials, such as database credentials, could potentially allow complete database takeover depending on the configuration. This vulnerability has not been known to be fixed yet.","date":"2023-04-18"},{"id":"40f126ff7bcf09af00b4470e0d7dac479ee727c8","name":"YARPP <= 5.30.4 - Authenticated (Subscriber+) Local File Inclusion","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/yet-another-related-posts-plugin\/yarpp-5302-authenticated-contributor-local-file-inclusion","description":"The YARPP plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 5.30.4 via the yarpp shortcode due to insufficient validation on the 'template' user attribute. This allows subscriber-level attackers, and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other \u201csafe\u201d file types can be uploaded and included.","date":"2023-04-18"},{"id":"b34976b3-54c3-45b7-86a0-387ee0a4b680","name":"YARPP - Yet Another Related Posts Plugin &lt; 5.30.5 - Subscriber+ LFI","link":"https:\/\/wpscan.com\/vulnerability\/b34976b3-54c3-45b7-86a0-387ee0a4b680","description":"The plugin does not validate a parameter before using it in an include statement, allowing any authenticated users, such as subscriber to perform LFI attacks","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"h","i":"n","a":"n","score":"7.7","severity":"h","exploitable":"2.8","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:H\/I:N\/A:N","score":"7.7","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"high","i":"none","a":"none","exploitable":"2.8","impact":"3.6"},"cwe":[{"cwe":"CWE-22","name":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","description":"The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"384ab6d249a14bc4e720967f3cb61539db68f9b53372016f4b42b1fdb13427b7","name":"YARPP &#8211; Yet Another Related Posts Plugin [yet-another-related-posts-plugin] < 5.30.3 (closed)","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.30.3","max_operator":"lt","unfixed":"0","closed":"1"},"source":[{"id":"CVE-2023-0579","name":"CVE-2023-0579","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-0579","description":"[en] The YARPP WordPress plugin before 5.30.3 does not validate and escape some of its shortcode attributes before using them in SQL statement\/s, which could allow any authenticated users, such as subscribers to perform SQL Injection attacks.","date":"2023-08-16"},{"id":"8e6a8ca30f518f543ca7351cf77a5cee3a1718c8","name":"WordPress  YARPP Plugin  < 5.30.3 is vulnerable to SQL Injection","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/yet-another-related-posts-plugin\/vulnerability\/wordpress-yarpp-plugin-5-30-3-subscriber-sqli-vulnerability","description":"Update the WordPress YARPP plugin to the latest available version (at least 5.30.3).\nErwan LR (WPScan) discovered and reported this SQL Injection vulnerability in WordPress YARPP Plugin. This could allow a malicious actor to directly interact with your database, including but not limited to stealing information. This vulnerability has been fixed in version 5.30.3.","date":"2023-05-03"},{"id":"6ae7ed3a2fae94e218c273152480df06548fbbed","name":"YARPP - Yet Another Related Posts Plugin <= 5.30.2 - Authenticated (Subscriber+) SQL Injection via Shortcode","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/yet-another-related-posts-plugin\/yarpp-yet-another-related-posts-plugin-5302-authenticated-subscriber-sql-injection-via-shortcode","description":"The YARRP plugin for WordPress is vulnerable to SQL Injection via the 'limit' parameter set via a shortcode in versions up to, and including, 5.30.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with subscriber-level permissions and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2023-04-25"},{"id":"574f7607-96d8-4ef8-b96c-0425ad7e7690","name":"YARPP - Yet Another Related Posts Plugin &lt; 5.30.3 - Subscriber+ SQLi","link":"https:\/\/wpscan.com\/vulnerability\/574f7607-96d8-4ef8-b96c-0425ad7e7690","description":"The plugin does not validate and escape some of its shortcode attributes before using them in SQL statement\/s, which could allow any authenticated users, such as subscribers to perform SQL Injection attacks.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"078849c492211ae6d9da4f36a439725086d1a3cde81db30fcf2f2c04311b6f17","name":"YARPP &#8211; Yet Another Related Posts Plugin [yet-another-related-posts-plugin] < 5.30.4 (closed)","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.30.4","max_operator":"lt","unfixed":"0","closed":"1"},"source":[{"id":"CVE-2023-2433","name":"CVE-2023-2433","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-2433","description":"[en] The YARPP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'className' parameter in versions up to, and including, 5.30.3 due to insufficient input sanitization and output escaping. This makes it possible for contributor-level attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2023-07-18"},{"id":"3dd0dbe686057b43456423820d5f809e279e4927","name":"YARPP \u2013 Yet Another Related Posts Plugin <= 5.30.3 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/yet-another-related-posts-plugin\/yarpp-yet-another-related-posts-plugin-5303-authenticated-contributor-stored-cross-site-scripting","description":"The YARPP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'className' parameter in versions up to, and including, 5.30.3 due to insufficient input sanitization and output escaping. This makes it possible for contributor-level attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2023-07-17"},{"id":"6672472c1fb64e133abeede7f57d8c75df274863","name":"WordPress  YARPP Plugin  <= 5.30.3 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/yet-another-related-posts-plugin\/vulnerability\/wordpress-yarpp-yet-another-related-posts-plugin-plugin-5-30-3-authenticated-contributor-stored-cross-site-scripting-vulnerability","description":"Update the WordPress YARPP plugin to the latest available version (at least 5.30.4).\nLana Codes discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress YARPP Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 5.30.4.","date":"2023-07-18"},{"id":"2858b67e-17ac-4a2a-8a46-24367d248454","name":"YARPP &lt; 5.30.4 - Contributor+ Stored Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/2858b67e-17ac-4a2a-8a46-24367d248454","description":"The plugin does not properly sanitize the &#039;className&#039; parameter, leading to Stored Cross-Site Scripting. Insufficient input sanitization and output escaping make it possible for contributors to inject arbitrary web scripts into pages.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"974580770b5d8b63ff0957de25ec7df1f9b430ea20d2d557cb081e7934f58f1c","name":"YARPP &#8211; Yet Another Related Posts Plugin [yet-another-related-posts-plugin] < 5.30.10 (closed)","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.30.10","max_operator":"lt","unfixed":"0","closed":"1"},"source":[{"id":"CVE-2024-0602","name":"CVE-2024-0602","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-0602","description":"[en] The YARPP \u2013 Yet Another Related Posts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.30.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.","date":"2024-02-20"},{"id":"faa6a9b1b137f76be7b891ebc72d2201dd003a57","name":"Yet Another Related Posts Plugin (YARPP) <= 5.30.9 - Authenticated(Administrator+) Stored Cross-Site Scripting via settings","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/yet-another-related-posts-plugin\/yet-another-related-posts-plugin-yarpp-5309-authenticatedadministrator-stored-cross-site-scripting-via-settings","description":"The YARPP \u2013 Yet Another Related Posts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.30.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.","date":"2024-02-20"},{"id":"9cfbfcf565743125ab58cc294f832c34f32b0730","name":"WordPress  YARPP Plugin  <= 5.30.9 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/yet-another-related-posts-plugin\/vulnerability\/wordpress-yarpp-plugin-5-30-9-authenticated-administrator-stored-cross-site-scripting-via-settings-vulnerability","description":"Update the WordPress YARPP plugin to the latest available version (at least 5.30.10).\nAkbar Kustirama discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress YARPP Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 5.30.10.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"05d24e91-3942-4af2-9791-4c7e7a39be97","name":"YARPP &lt; 5.30.10 - Admin+ Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/05d24e91-3942-4af2-9791-4c7e7a39be97","description":"The plugin does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"h","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"4.0","severity":"m","exploitable":"1.0","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"4.0","severity":"medium","av":"network","ac":"high","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"1.0","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."},{"cwe":"CWE-80","name":"Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)","description":"The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as \"<\", \">\", and \"&\" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"bce09fd4aed9ba7d74dde9cd34e626a58d63a0d185f36ff3da908de50389bfb9","name":"YARPP &#8211; Yet Another Related Posts Plugin [yet-another-related-posts-plugin] < 5.30.10 (closed)","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.30.10","max_operator":"lt","unfixed":"0","closed":"1"},"source":[{"id":"CVE-2023-6495","name":"CVE-2023-6495","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-6495","description":"[en] The YARPP \u2013 Yet Another Related Posts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to and including 5.30.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.","date":"2024-06-19"},{"id":"535901d9c3acc47fc4390fbcf988d0975b5a73e0","name":"YARPP \u2013 Yet Another Related Posts Plugin <= 5.30.9 - Authenticated(Administrator+) Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/yet-another-related-posts-plugin\/yarpp-yet-another-related-posts-plugin-5309-authenticatedadministrator-cross-site-scripting","description":"The YARPP \u2013 Yet Another Related Posts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to and including 5.30.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.","date":"2024-06-18"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"4.8","severity":"m","exploitable":"1.7","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"4.8","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"1.7","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"46eb9bb30aba089dc4dd895c95e44b3c5a1f0d849891ab1d41b56738c348e89f","name":"YARPP &#8211; Yet Another Related Posts Plugin [yet-another-related-posts-plugin] < 5.30.11 (closed)","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.30.11","max_operator":"lt","unfixed":"0","closed":"1"},"source":[{"id":"CVE-2024-43919","name":"CVE-2024-43919","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-43919","description":"[en] Access Control vulnerability in YARPP YARPP allows .\n\nThis issue affects YARPP: from n\/a through 5.30.10.","date":"2024-11-01"},{"id":"090bee580f81f699d592bc9f8fd343b71026032a","name":"WordPress YARPP Plugin <= 5.30.10 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/yet-another-related-posts-plugin\/vulnerability\/wordpress-yet-another-related-posts-plugin-yarpp-plugin-5-30-10-broken-access-control-vulnerability","description":"<p>WordPress YARPP Plugin <= 5.30.10 is vulnerable to Broken Access Control<\/p><p>Software: YARPP<\/p><p>Link: https:\/\/wordpress.org\/plugins\/yet-another-related-posts-plugin\/#developers<\/p><p>Affected Version <= 5.30.10<\/p>","date":"2024-08-26"},{"id":"6f3a36a07ed77cedefb5789aa7cc59dbac053aa7","name":"YARPP <= 5.30.10 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/yet-another-related-posts-plugin\/yarpp-53010-missing-authorization","description":"The YARPP \u2013 Yet Another Related Posts Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check in the ~\/includes\/yarpp_pro_set_display_types.php file in all versions up to, and including, 5.30.10. This makes it possible for unauthenticated attackers to set display types.","date":"2024-08-26"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"9.8","severity":"c","exploitable":"3.9","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"9.8","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"3.9","impact":"5.9"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}}]},"updated":"1783818199"}