CVEs (7)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Yarpp 1Yet Another Related Posts Plugin Jun 17, 2026 Nov 1, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Access Control vulnerability in YARPP YARPP allows .
This issue affects YARPP: from n/a through 5.30.10. |
1Yarpp 1Yet Another Related Posts Plugin Jun 17, 2026 Jun 19, 2024 N/A· v4 4.8 MEDIUM· v3 N/A· v2 The YARPP – Yet Another Related Posts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to and including 5.30.9 due to insufficient input sanitization and outp...Show more |
1Yarpp 1Yet Another Related Posts Plugin Jun 17, 2026 May 17, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in YARPP allows PHP Local File Inclusion.This issue affects YARPP: from n/a through 5.30.4. |
1Yarpp 1Yet Another Related Posts Plugin Jun 17, 2026 Feb 29, 2024 N/A· v4 4.0 MEDIUM· v3 N/A· v2 The YARPP – Yet Another Related Posts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.30.9 due to insufficient input sanitization and ou...Show more |
1Yarpp 2Yarpp Yet Another Related Posts PluginJun 17, 2026 Aug 16, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 The YARPP WordPress plugin before 5.30.3 does not validate and escape some of its shortcode attributes before using them in SQL statement/s, which could allow any authenticated users, such as subscribers to perform SQL I...Show more |
1Yarpp 1Yet Another Related Posts Plugin Jun 17, 2026 Jul 18, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The YARPP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'className' parameter in versions up to, and including, 5.30.3 due to insufficient input sanitization and output escaping. This makes it pos...Show more |
1Yarpp 1Yet Another Related Posts Plugin Jun 17, 2026 Feb 13, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The YARPP WordPress plugin before 5.30.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor...Show more |