YellowPencil Vulnerabilities and Affected Products
Vulnerabilities associated with visual_css_style_editor.
Products
Clear product- visual_css_style_editor1 vulnerability
- YellowPencil Visual CSS Style Editor1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2019-11886HIGH | yellowpencil visual_css_style_editor Cross-Site Request Forgery (CSRF)The WaspThemes Visual CSS Style Editor (aka yellow-pencil-visual-theme-customizer) plugin before 7.2.1 for WordPress allows yp_option_update CSRF, as demonstrated by use of yp_remote_get to obtain admin access. | CVSS8.8v3.0 | EPSS1.89% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |