CVE-2019-11869
MEDIUM EXPLOITED NUCLEIYuzo Related Posts 5.12.94 - XSS
Title source: llmDescription
The Yuzo Related Posts plugin 5.12.94 for WordPress has XSS because it mistakenly expects that is_admin() verifies that the request comes from an admin user (it actually only verifies that the request is for an admin page). An unauthenticated attacker can inject a payload into the plugin settings, such as the yuzo_related_post_css_and_style setting.
Exploits (1)
Nuclei Templates (1)
WordPress Yuzo <5.12.94 - Cross-Site Scripting
MEDIUMby ganofins
References (3)
Scores
CVSS v3
6.1
EPSS
0.1137
EPSS Percentile
93.6%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
VulnCheck KEV
2019-05-09
CWE
CWE-79
Status
published
Products (1)
yuzopro/yuzo
5.12.94
Published
May 09, 2019
Tracked Since
Feb 18, 2026