plugin

Yet Another Related Posts Plugin Vulnerabilities

18 known security issues reported for the Yet Another Related Posts Plugin WordPress plugin. Most recent disclosed Nov 1, 2024.

1 critical 2 high 5 medium

Running Yet Another Related Posts Plugin on your site? Check whether your installed version is affected.

Scan your site free

YARPP &#8211; Yet Another Related Posts Plugin [yet-another-related-posts-plugin] < 5.30.11

unknown

[en] Access Control vulnerability in YARPP YARPP allows . This issue affects YARPP: from n/a through 5.30.10.

Affected:
up to 5.30.11
Fixed in:
5.30.11
Disclosed:
Nov 1, 2024

CVE-2024-43919 on NVD →

YARPP <= 5.30.10 - Missing Authorization

medium

The YARPP – Yet Another Related Posts Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check in the ~/includes/yarpp_pro_set_display_types.php file in all versions up to, and including, 5.30.10. This makes it possible for unauthenticated attackers to set display types.

CVSS:
5.3
Affected:
up to 5.30.10
Fixed in:
5.30.11
Disclosed:
Aug 26, 2024

CVE-2024-43919 on NVD →

YARPP &#8211; Yet Another Related Posts Plugin [yet-another-related-posts-plugin] < 5.30.10

unknown

[en] The YARPP – Yet Another Related Posts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to and including 5.30.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permi...

Affected:
up to 5.30.10
Fixed in:
5.30.10
Disclosed:
Jun 19, 2024

CVE-2023-6495 on NVD →

YARPP – Yet Another Related Posts Plugin <= 5.30.9 - Authenticated(Administrator+) Cross-Site Scripting

medium

The YARPP – Yet Another Related Posts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to and including 5.30.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permission...

CVSS:
4.4
Affected:
up to 5.30.9
Fixed in:
5.30.10
Disclosed:
Jun 18, 2024

CVE-2023-6495 on NVD →

YARPP &#8211; Yet Another Related Posts Plugin [yet-another-related-posts-plugin] < 5.30.5

unknown

[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in YARPP allows PHP Local File Inclusion.This issue affects YARPP: from n/a through 5.30.4.

Affected:
up to 5.30.5
Fixed in:
5.30.5
Disclosed:
May 17, 2024

CVE-2022-45374 on NVD →

Yet Another Related Posts Plugin (YARPP) <= 5.30.9 - Authenticated(Administrator+) Stored Cross-Site Scripting via settings

medium

The YARPP – Yet Another Related Posts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.30.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissi...

CVSS:
4.4
Affected:
up to 5.30.9
Fixed in:
5.30.10
Disclosed:
Feb 20, 2024

CVE-2024-0602 on NVD →

YARPP &#8211; Yet Another Related Posts Plugin [yet-another-related-posts-plugin] < 5.30.10

unknown

[en] The YARPP – Yet Another Related Posts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.30.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level per...

Affected:
up to 5.30.10
Fixed in:
5.30.10
Disclosed:
Feb 20, 2024

CVE-2024-0602 on NVD →

YARPP &#8211; Yet Another Related Posts Plugin [yet-another-related-posts-plugin] < 5.30.3

unknown

[en] The YARPP WordPress plugin before 5.30.3 does not validate and escape some of its shortcode attributes before using them in SQL statement/s, which could allow any authenticated users, such as subscribers to perform SQL Injection attacks.

Affected:
up to 5.30.3
Fixed in:
5.30.3
Disclosed:
Aug 16, 2023

CVE-2023-0579 on NVD →

YARPP &#8211; Yet Another Related Posts Plugin [yet-another-related-posts-plugin] < 5.30.4

unknown

[en] The YARPP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'className' parameter in versions up to, and including, 5.30.3 due to insufficient input sanitization and output escaping. This makes it possible for contributor-level attackers to inject arbitrary web scripts in pages that will execut...

Affected:
up to 5.30.4
Fixed in:
5.30.4
Disclosed:
Jul 18, 2023

CVE-2023-2433 on NVD →

YARPP – Yet Another Related Posts Plugin <= 5.30.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The YARPP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'className' parameter in versions up to, and including, 5.30.3 due to insufficient input sanitization and output escaping. This makes it possible for contributor-level attackers to inject arbitrary web scripts in pages that will execute whe...

CVSS:
6.4
Affected:
up to 5.30.3
Fixed in:
5.30.4
Disclosed:
Jul 17, 2023

CVE-2023-2433 on NVD →

YARPP - Yet Another Related Posts Plugin <= 5.30.2 - Authenticated (Subscriber+) SQL Injection via Shortcode

high

The YARRP plugin for WordPress is vulnerable to SQL Injection via the 'limit' parameter set via a shortcode in versions up to, and including, 5.30.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attacke...

CVSS:
8.8
Affected:
up to 5.30.3
Fixed in:
5.30.3
Disclosed:
Apr 25, 2023

CVE-2023-0579 on NVD →

YARPP <= 5.30.4 - Authenticated (Subscriber+) Local File Inclusion

high

The YARPP plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 5.30.4 via the yarpp shortcode due to insufficient validation on the 'template' user attribute. This allows subscriber-level attackers, and above, to include and execute arbitrary files on the server, allowing the exe...

CVSS:
8.8
Affected:
up to 5.30.4
Fixed in:
5.30.5
Disclosed:
Apr 18, 2023

CVE-2022-45374 on NVD →

YARPP &#8211; Yet Another Related Posts Plugin [yet-another-related-posts-plugin] < 5.30.3

unknown

[en] The YARPP WordPress plugin before 5.30.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

Affected:
up to 5.30.3
Fixed in:
5.30.3
Disclosed:
Feb 13, 2023

CVE-2022-4471 on NVD →

YARPP – Yet Another Related Posts Plugin <= 5.30.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The YARPP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 5.30.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor level and above per...

CVSS:
6.4
Affected:
up to 5.30.2
Fixed in:
5.30.3
Disclosed:
Jan 19, 2023

CVE-2022-4471 on NVD →

YARPP – Yet Another Related Posts Plugin < 4.2.5 - Cross-Site Request Forgery

critical

The YARPP – Yet Another Related Posts Plugin for WordPress is vulnerable a Cross-Site Request Forgery which can lead to Remote Code Execution in versions up to, and including, 4.2.4 via the yarpp_options.php file. This allows unauthenticated attackers to execute code on the server if they can successfully trick an admi...

CVSS:
9.8
Affected:
up to 4.2.5
Fixed in:
4.2.5
Disclosed:
May 8, 2015

YARPP &#8211; Yet Another Related Posts Plugin [yet-another-related-posts-plugin] < 4.2.5

unknown

WordPress Yet Another Related Posts plugin is prone to a cross-site request forgery vulnerability. It allows an attacker to gain unauthorized access to the affected application by performing certain actions in the context of an authorized user's session. Upgrade the plugin.

Affected:
up to 4.2.5
Fixed in:
4.2.5
Disclosed:
May 8, 2015

YARPP &#8211; Yet Another Related Posts Plugin [yet-another-related-posts-plugin] < 4.2.5

unknown

The YARPP – Yet Another Related Posts Plugin for WordPress is vulnerable a Cross-Site Request Forgery which can lead to Remote Code Execution in versions up to, and including, 4.2.4 via the yarpp_options.php file. This allows unauthenticated attackers to execute code on the server if they can successfully trick an admi...

Affected:
up to 4.2.5
Fixed in:
4.2.5
Disclosed:
May 8, 2015

YARPP &#8211; Yet Another Related Posts Plugin [yet-another-related-posts-plugin] < 4.2.5

unknown

&#039;Yet Another Related Posts Plugin&#039; options can be updated with no token/nonce protection which an attacker may exploit via tricking website&#039;s administrator to enter a malformed page which will change YARPP options, and since some options allow html the attacker is able to inject malformed javascript code...

Affected:
up to 4.2.5
Fixed in:
4.2.5

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database