Yarpp is a narrowly focused WordPress plugin that generates related-post recommendations and sits within the content-management layer of many WordPress installations. Vulnerabilities affecting the vendor skew toward serious outcomes and frequently acquire public exploit code; the exposure recurs through web-application weakness classes including cross-site scripting, path traversal, SQL injection, and missing authorization that are typical of server-side content plugins. Defenders tracking WordPress deployments should monitor this plugin's update cycle and treat disclosed flaws as requiring timely remediation; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yarpp over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-43919CRITICAL Access Control vulnerability in YARPP YARPP allows .
This issue affects YARPP: from n/a through 5.30.10. | Nov 1, 2024 | 9.8 | 61 | NO | YES |
CVE-2023-0579HIGH The YARPP WordPress plugin before 5.30.3 does not validate and escape some of its shortcode attributes before using them in SQL statement/s, which could allow any authenticated use | Aug 16, 2023 | 8.8 | 22 | NO | NO |
CVE-2022-45374MEDIUM Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in YARPP allows PHP Local File Inclusion.This issue affects YARPP: from n/a through 5.3 | May 17, 2024 | 6.5 | 21 | NO | NO |
CVE-2022-4471MEDIUM The YARPP WordPress plugin before 5.30.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, whic | Feb 13, 2023 | 5.4 | 19 | NO | NO |
CVE-2023-2433MEDIUM The YARPP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'className' parameter in versions up to, and including, 5.30.3 due to insufficient input sanitizatio | Jul 18, 2023 | 5.4 | 18 | NO | NO |
CVE-2023-6495MEDIUM The YARPP – Yet Another Related Posts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to and including 5.30.9 due to | Jun 19, 2024 | 4.8 | 17 | NO | NO |
CVE-2024-0602MEDIUM The YARPP – Yet Another Related Posts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.30.9 due t | Feb 29, 2024 | 4.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yarpp.
Media articles that mention a CVE ID that affects a product developed by Yarpp — matched by CVE ID, not by vendor name.