The YARPP – Yet Another Related Posts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to and including 5.30.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
We have discovered 9,715 live websites that are affected by CVE-2023-6495.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 9,715 live websites (29.28% of Yet Another Related Posts Plugin install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 174 versions ( 95.08% of all versions) |
![]() | 3,212 websites |
![]() | 1,541 websites |
![]() | 1,361 websites |
![]() | 706 websites |
![]() | 615 websites |
![]() | 239 websites |
![]() | 127 websites |
![]() | 109 websites |
![]() | 108 websites |
.com | 4,252 websites |
.ru | 1,655 websites |
.net | 547 websites |
.org | 390 websites |
.fr | 286 websites |
.de | 260 websites |
.jp | 248 websites |
.pl | 245 websites |
.info | 131 websites |
.es | 122 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
******.com | ![]() | *,*** | |
*****.jp | ![]() | **,*** | |
**********.net | ![]() | **,*** | |
************.com | ![]() | **,*** | |
**********************.com | ![]() | **,*** | |
**************.jp | ![]() | **,*** | |
*********.com | ![]() | **,*** | |
************.org | ![]() | **,*** | |
*******.*******.pt | ![]() | **,*** | |
*************.org | ![]() | **,*** |
FAQ