CVE-2023-0579: YARPP - Yet Another Related Posts Plugin < 5.30.3 - Subscriber+ SQLi
Published Aug 16, 2023
·Updated
The YARPP WordPress plugin before 5.30.3 does not validate and escape some of its shortcode attributes before using them in SQL statement/s, which could allow any authenticated users, such as subscribers to perform SQL Injection attacks.
Affected Software
2 affected components
YARPP YARPP WordPress<5.30.3
YARPP Yet Another Related Posts Plugin Wordpress<5.30.3
Event History
Aug 16, 2023
CVE Published
via MITRE·11:03 AM
Data Sourced
via MITRE·11:03 AM
DescriptionWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-0579?
CVE-2023-0579 is considered a high severity vulnerability due to the potential for SQL Injection attacks.
2
How do I fix CVE-2023-0579?
To fix CVE-2023-0579, update the YARPP WordPress plugin to version 5.30.3 or later.
3
Who is affected by CVE-2023-0579?
CVE-2023-0579 affects any authenticated user of the YARPP WordPress plugin versions prior to 5.30.3.
4
What type of vulnerability is CVE-2023-0579?
CVE-2023-0579 is an SQL Injection vulnerability caused by the lack of validation and escaping of shortcode attributes.
5
Can CVE-2023-0579 be exploited remotely?
CVE-2023-0579 cannot be exploited remotely as it requires authenticated user access to the WordPress site.