plugin

Yellow Pencil Visual Theme Customizer Vulnerabilities

11 known security issues reported for the Yellow Pencil Visual Theme Customizer WordPress plugin. Most recent disclosed Oct 6, 2024.

1 critical 4 medium

Running Yellow Pencil Visual Theme Customizer on your site? Check whether your installed version is affected.

Scan your site free

Visual CSS Style Editor [yellow-pencil-visual-theme-customizer] < 7.6.5

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WaspThemes YellowPencil Visual CSS Style Editor allows Reflected XSS.This issue affects YellowPencil Visual CSS Style Editor: from n/a through 7.6.4.

Affected:
up to 7.6.5
Fixed in:
7.6.5
Disclosed:
Oct 6, 2024

CVE-2024-47348 on NVD →

YellowPencil Visual CSS Style Editor <= 7.6.4 - Reflected Cross-Site Scripting

medium

The YellowPencil Visual CSS Style Editor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 7.6.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if...

CVSS:
6.1
Affected:
up to 7.6.4
Fixed in:
7.6.5
Disclosed:
Sep 30, 2024

CVE-2024-47348 on NVD →

Visual CSS Style Editor [yellow-pencil-visual-theme-customizer] < 7.6.4

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WaspThemes YellowPencil Visual CSS Style Editor allows Reflected XSS.This issue affects YellowPencil Visual CSS Style Editor: from n/a through 7.6.1.

Affected:
up to 7.6.4
Fixed in:
7.6.4
Disclosed:
Aug 29, 2024

CVE-2024-43963 on NVD →

YellowPencil Visual CSS Style Editor <= 7.6.1 - Reflected Cross-Site Scripting

medium

The Visual CSS Style Editor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 7.6.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can...

CVSS:
6.1
Affected:
up to 7.6.1
Fixed in:
7.6.4
Disclosed:
Aug 26, 2024

CVE-2024-43963 on NVD →

Visual CSS Style Editor [yellow-pencil-visual-theme-customizer] < 7.5.9

unknown

[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WaspThemes Visual CSS Style Editor plugin <= 7.5.8 versions.

Affected:
up to 7.5.9
Fixed in:
7.5.9
Disclosed:
May 10, 2023

CVE-2022-33961 on NVD →

YellowPencil Visual CSS Style Editor <= 7.5.8 - Reflected Cross-Site Scripting liveLink

medium

The YellowPencil Visual CSS Style Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the liveLink parameter in versions up to, and including, 7.5.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts i...

CVSS:
6.1
Affected:
up to 7.5.8
Fixed in:
7.5.9
Disclosed:
Apr 18, 2023

CVE-2022-33961 on NVD →

Visual CSS Style Editor [yellow-pencil-visual-theme-customizer] < 7.5.4

unknown

[en] The Visual CSS Style Editor WordPress plugin before 7.5.4 does not sanitise and escape the wyp_page_type parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue

Affected:
up to 7.5.4
Fixed in:
7.5.4
Disclosed:
Feb 1, 2022

CVE-2021-24934 on NVD →

Visual CSS Style Editor <= 7.5.3 - Reflected Cross-Site Scripting via wyp_page_type parameter

medium

The Visual CSS Style Editor WordPress plugin before 7.5.4 does not sanitise and escape the wyp_page_type parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue

CVSS:
6.1
Affected:
up to 7.5.3
Fixed in:
7.5.4
Disclosed:
Jan 3, 2022

CVE-2021-24934 on NVD →

Visual CSS Style Editor [yellow-pencil-visual-theme-customizer] < 7.2.1

unknown

[en] The WaspThemes Visual CSS Style Editor (aka yellow-pencil-visual-theme-customizer) plugin before 7.2.1 for WordPress allows yp_option_update CSRF, as demonstrated by use of yp_remote_get to obtain admin access.

Affected:
up to 7.2.1
Fixed in:
7.2.1
Disclosed:
May 13, 2019

CVE-2019-11886 on NVD →

Visual CSS Style Editor [yellow-pencil-visual-theme-customizer] < 7.2.1

unknown

Unauthenticated arbitrary Options update vulnerability found in WordPress YellowPencil Visual CSS Style Editor plugin (versions <= 7.2.0).

Affected:
up to 7.2.1
Fixed in:
7.2.1
Disclosed:
Apr 12, 2019

Visual CSS Style Editor <= 7.2.0 - Unauthenticated Arbitrary Options Update

critical

The WaspThemes Visual CSS Style Editor (aka yellow-pencil-visual-theme-customizer) plugin before 7.2.1 for WordPress allows yp_option_update by unauthenticated users and lacks CSRF protection, as demonstrated by use of yp_remote_get to obtain admin access.

CVSS:
9.8
Affected:
up to 7.2.1
Fixed in:
7.2.1
Disclosed:
Apr 11, 2019

CVE-2019-11886 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database