CVE-2022-4471: YARPP - Yet Another Related Posts Plugin < 5.30.3 - Contributor+ Stored XSS
The YARPP WordPress plugin before 5.30.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-4471?
CVE-2022-4471 has a moderate severity rating due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2022-4471?
To fix CVE-2022-4471, update the YARPP WordPress plugin to version 5.30.3 or later.
What types of attacks can CVE-2022-4471 facilitate?
CVE-2022-4471 can facilitate Stored Cross-Site Scripting (XSS) attacks, potentially compromising user sessions.
Who is affected by CVE-2022-4471?
CVE-2022-4471 affects users with the contributor role and above who can embed the vulnerable shortcode.
What versions of the YARPP plugin are vulnerable to CVE-2022-4471?
Versions of the YARPP plugin before 5.30.3, specifically up to and including 5.30.1, are vulnerable to CVE-2022-4471.