Record summary

CVE-2019-11886 has a selected CVSS score of 8.8 (high); EIP currently links 1 Nuclei template.

Description

The WaspThemes Visual CSS Style Editor (aka yellow-pencil-visual-theme-customizer) plugin before 7.2.1 for WordPress allows yp_option_update CSRF, as demonstrated by use of yp_remote_get to obtain admin access.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Apr 11, 2019 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryHIGHYellow Pencil Visual Theme Customizer < 7.2.1 - Privilege EscalationCVSS 8.8

The WaspThemes Visual CSS Style Editor (aka yellow-pencil-visual-theme-customizer) plugin before 7.2.1 for WordPress allows yp_option_update CSRF, as demonstrated by use of yp_remote_get to obtain admin access.

Impact

Unauthenticated attackers can exploit CSRF to escalate privileges to administrator level, gaining complete control over the WordPress site including content manipulation and user management.

Remediation

Upgrade to Yellow Pencil Visual Theme Customizer version 7.2.1 or later.

WeaknessesCWE-352
Authorsdaffainfo
Template tagscvecve2019wpwordpresswp-pluginyellow-pencil-visual-theme-customizervkevvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:yellowpencil:visual_css_style_editor:*:*:*:*:*:wordpress:*:*
FOFA: body="wp-content/plugins/yellow-pencil-visual-theme-customizer/" && body="wp-"

Source: ProjectDiscovery

References

5