CVE-2025-14545

YML for Yandex Market < 5.0.26 - Shop Manager+ RCE via Feed Generation

The YML for Yandex Market WordPress plugin before 5.0.26 is vulnerable to Remote Code Execution via the feed generation process.


We have discovered 801 live websites that are affected by CVE-2025-14545.

Run a Free Instant Scan




Affected Software

Product  Yml For Yandex Market
Category Wordpress Plugins
Vulnerable Domains801 live websites (79% of Yml For Yandex Market install base)
Vulnerable Versions
  • from 0 through 5.0.26
Vulnerable Versions Count23 versions ( 96% of all versions)


Common Weakness Enumeration

CWE-94 Improper Control of Generation of Code ('Code Injection')



Details

  • Published - Apr 10, 2026
  • Updated - Apr 10, 2026

Credits

  • Alex Tselevich (nos3curity) (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2025-14545
United States1 websites



Russia751 websites
Belarus26 websites
Ukraine10 websites
Kazakhstan7 websites
Uzbekistan2 websites
Austria1 websites
Germany1 websites
GB1 websites
South Africa1 websites

Website Distribution by TLD

Number of websites using CVE-2025-14545
.ru629 websites
.com40 websites
.net2 websites
.org2 websites
.at1 websites
.co1 websites
.info1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-14545

Top websites that are affected by CVE-2025-14545. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.ru Russia*,***,***
********.ru Russia*,***,***
******.ru Russia*,***,***
*******.mobi Russia*,***,***
*******.ru Russia*,***,***
********.ru Russia*,***,***
****.ru Russia*,***,***
*********.ru Russia*,***,***
***********.ru Russia*,***,***
***********.ru Russia*,***,***
See full domain list

FAQ

CVE-2025-14545 is Improper Control of Generation of Code ('Code Injection') in Yml For Yandex Market
A total of 801 websites have been identified as vulnerable to CVE-2025-14545, based on global website indexing conducted by WebTechSurvey.
The Yml For Yandex Market is affected by the CVE-2025-14545 vulnerability.
Yml For Yandex Market versions up to 5.0.26 are vulnerable to CVE-2025-14545.
CVE-2025-14545 is resolved in version 5.0.26 of Yml For Yandex Market.