plugin

Yawpp Vulnerabilities

2 known security issues reported for the Yawpp WordPress plugin. Most recent disclosed Dec 9, 2015.

1 high 1 medium

Running Yawpp on your site? Check whether your installed version is affected.

Scan your site free

YAWPP (Yet Another WordPress Petition Plugin) <= 1.2.2 - Cross-Site Scripting

medium

The yawpp plugin through 1.2.2 for WordPress has XSS via the field1 parameter.

CVSS:
6.1
Affected:
up to 1.2.2
Fix:
No patched version reported
Disclosed:
Dec 9, 2015

CVE-2015-9391 on NVD →

YAWPP (Yet Another WordPress Petition Plugin) <= 1.2.1 - Authenticated SQL Injection

high

Multiple SQL injection vulnerabilities in the yawpp plugin 1.2.1 for WordPress allow remote authenticated users with Contributor privileges to execute arbitrary SQL commands via vectors related to (1) admin_functions.php or (2) admin_update.php, as demonstrated by the id parameter in the update action to wp-admin/admin...

CVSS:
8.8
Affected:
up to 1.2.1
Fixed in:
1.2.2
Disclosed:
May 28, 2014

CVE-2014-5182 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database