Extension WordPress

Vulnérabilités YARPP – Yet Another Related Posts Plugin

Cette page rassemble les failles publiées pour YARPP – Yet Another Related Posts Plugin, leurs plages de versions affectées et les correctifs signalés dans la base locale.

8Vulnérabilités
1Critiques
8Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de YARPP – Yet Another Related Posts Plugin

8 fiches

CVE-2023-6495 Moyenne · 4,4
YARPP – Yet Another Related Posts Plugin

YARPP – Yet Another Related Posts Plugin <= 5.30.9 – Authenticated(Administrator+) Cross-Site Scripting

The YARPP – Yet Another Related Posts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to and including 5.30.9 due to insufficient input sanitization and output escaping. This makes…

Versions affectées

*-5.30.9

Correctif

5.30.10

Publication

18/06/2024

CVE-2024-0602 Moyenne · 4,4
YARPP – Yet Another Related Posts Plugin

Yet Another Related Posts Plugin (YARPP) <= 5.30.9 – Authenticated(Administrator+) Stored Cross-Site Scripting via settings

The YARPP – Yet Another Related Posts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.30.9 due to insufficient input sanitization and output escaping. This makes…

Versions affectées

*-5.30.9

Correctif

5.30.10

Publication

20/02/2024

CVE-2023-2433 Moyenne · 6,4
YARPP – Yet Another Related Posts Plugin

YARPP – Yet Another Related Posts Plugin <= 5.30.3 – Authenticated (Contributor+) Stored Cross-Site Scripting

The YARPP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'className' parameter in versions up to, and including, 5.30.3 due to insufficient input sanitization and output escaping. This makes it possible for contributor-level attackers to inject…

Versions affectées

*-5.30.3

Correctif

5.30.4

Publication

17/07/2023

CVE-2023-0579 Élevée · 8,8
YARPP – Yet Another Related Posts Plugin

YARPP – Yet Another Related Posts Plugin <= 5.30.2 – Authenticated (Subscriber+) SQL Injection via Shortcode

The YARRP plugin for WordPress is vulnerable to SQL Injection via the 'limit' parameter set via a shortcode in versions up to, and including, 5.30.2 due to insufficient escaping on the user supplied parameter and lack of sufficient…

Versions affectées

[*, 5.30.3)

Correctif

5.30.3

Publication

25/04/2023

CVE-2022-4471 Moyenne · 6,4
YARPP – Yet Another Related Posts Plugin

YARPP – Yet Another Related Posts Plugin <= 5.30.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The YARPP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 5.30.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible…

Versions affectées

*-5.30.2

Correctif

5.30.3

Publication

19/01/2023

Vulnérabilité Critique · 9,8
YARPP – Yet Another Related Posts Plugin

YARPP – Yet Another Related Posts Plugin < 4.2.5 – Cross-Site Request Forgery

The YARPP – Yet Another Related Posts Plugin for WordPress is vulnerable a Cross-Site Request Forgery which can lead to Remote Code Execution in versions up to, and including, 4.2.4 via the yarpp_options.php file. This allows unauthenticated attackers…

Versions affectées

[*, 4.2.5)

Correctif

4.2.5

Publication

08/05/2015

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités