Lucene search

K

YARPP Security Vulnerabilities

cve
cve

CVE-2022-45374

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in YARPP allows PHP Local File Inclusion.This issue affects YARPP: from n/a through...

7.7CVSS

6.8AI Score

0.0004EPSS

2024-05-17 07:15 AM
58
cve
cve

CVE-2023-2433

The YARPP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'className' parameter in versions up to, and including, 5.30.3 due to insufficient input sanitization and output escaping. This makes it possible for contributor-level attackers to inject arbitrary web scripts in pages....

6.4CVSS

5.3AI Score

0.001EPSS

2023-07-18 09:15 AM
20
cve
cve

CVE-2023-0579

The YARPP WordPress plugin before 5.30.3 does not validate and escape some of its shortcode attributes before using them in SQL statement/s, which could allow any authenticated users, such as subscribers to perform SQL Injection...

8.8CVSS

8.9AI Score

0.001EPSS

2023-08-16 12:15 PM
39
cve
cve

CVE-2022-4471

The YARPP WordPress plugin before 5.30.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting...

5.4CVSS

5.3AI Score

0.001EPSS

2023-02-13 03:15 PM
49