Yuzo Related Posts <= 5.12.93 - Missing Authorization to Stored Cross-Site Scripting
highThe Yuzo Related Posts plugin 5.12.94 for WordPress has XSS because it mistakenly expects that is_admin() verifies that the request comes from an admin user (it actually only verifies that the request is for an admin page). An unauthenticated attacker can inject a payload into the plugin settings, such as the yuzo_rela...
- CVSS:
- 7.2
- Affected:
- up to 5.12.94
- Fixed in:
- 5.12.94
- Disclosed:
- Apr 10, 2019