Showing 1 vulnerability on this page for visual_css_style_editor

Signals CISA KEV Ransomware Nuclei
YellowPencil vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

yellowpencil visual_css_style_editor Cross-Site Request Forgery (CSRF)

The WaspThemes Visual CSS Style Editor (aka yellow-pencil-visual-theme-customizer) plugin before 7.2.1 for WordPress allows yp_option_update CSRF, as demonstrated by use of yp_remote_get to obtain admin access.

CWE-352May 13, 20191 related artifact
CVSS8.8v3.0EPSS1.89%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX