cleantalk
Vulnerabilities and Security Researches

YARPP – Yet Another Related Posts Plugin, CVE-2023-0579

CVE, Research URL

CVE-2023-0579

Published on
Aug 16, 2023
Research Description
The YARPP WordPress plugin before 5.30.3 does not validate and escape some of its shortcode attributes before using them in SQL statement/s, which could allow any authenticated users, such as subscribers to perform SQL Injection attacks.
Affected versions
Min -, max 5.30.3.
Status
vulnerable