Yet Another Related Posts Plugin
Vendor:
First CVE: Feb 13, 2023 · Active for 3 years
7
Total CVEs
More Total CVEs than 85% of tracked products
3.5
Avg CVEs / Year
Higher CVE frequency than 84% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 31% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Yet Another Related Posts Plugin over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 13, 2023
3 years ago
Most Recent CVE
Nov 1, 2024
634 days ago
CVE Severity & Scoring
Yet Another Related Posts Plugin7 CVEs
71%
14%
14%
All CVEs353,173 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network7 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (85.7%)
High1 (14.3%)
Unknown0 (0.0%)
User Interaction
None3 (42.9%)
Unknown0 (0.0%)
Required4 (57.1%)
Privileges Required
Low4 (57.1%)
High2 (28.6%)
None1 (14.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-43919CRITICAL Access Control vulnerability in YARPP YARPP allows .
This issue affects YARPP: from n/a through 5.30.10. | Nov 1, 2024 | 9.8 | 61 | NO | YES |
CVE-2023-0579HIGH The YARPP WordPress plugin before 5.30.3 does not validate and escape some of its shortcode attributes before using them in SQL statement/s, which could allow any authenticated use | Aug 16, 2023 | 8.8 | 22 | NO | NO |
CVE-2022-45374MEDIUM Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in YARPP allows PHP Local File Inclusion.This issue affects YARPP: from n/a through 5.3 | May 17, 2024 | 6.5 | 21 | NO | NO |
CVE-2022-4471MEDIUM The YARPP WordPress plugin before 5.30.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, whic | Feb 13, 2023 | 5.4 | 19 | NO | NO |
CVE-2023-2433MEDIUM The YARPP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'className' parameter in versions up to, and including, 5.30.3 due to insufficient input sanitizatio | Jul 18, 2023 | 5.4 | 18 | NO | NO |
CVE-2023-6495MEDIUM The YARPP – Yet Another Related Posts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to and including 5.30.9 due to | Jun 19, 2024 | 4.8 | 17 | NO | NO |
CVE-2024-0602MEDIUM The YARPP – Yet Another Related Posts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.30.9 due t | Feb 29, 2024 | 4.0 | 15 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (7 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
14.3% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (7 CVEs).
Media Mentions
Signals from CVEs in this product scope (7 CVEs).
Top CNAs Publishing CVEs For Yet Another Related Posts Plugin
Top CWEs
Versions
No cataloged versions.