CVE-2026-73397: WordPress Youzify plugin <= 1.3.7 - Deserialization of untrusted data vulnerability
Published Aug 18, 2026
·Updated
Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions.
Affected Software
1 affected component
WordPress Youzify plugin<=1.3.7
Event History
Aug 18, 2026
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The vulnerability is remotely reachable and requires no authentication or user interaction. The provided severity vector indicates that successful exploitation can affect confidentiality, integrity, and availability at a high level.
2
Which installations are known to be affected?
Youzify versions 1.3.7 and earlier are identified as affected. The provided data does not state which version contains a fix or any temporary mitigation.