CVE · High

CVE-2019-11886 — Visual CSS Style Editor [yellow-pencil-visual-theme-customizer] < 7.2.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2019-11886 Visual CSS Style Editor [yellow-pencil-visual-theme-customizer] < 7.2.1 Cross-Site Request Forgery (CSRF) High 8.8 < 7.2.1 7.2.1 2019-04-11

CVE-2019-11886

The Visual CSS Style Editor plugin for WordPress versions before 7.2.1 contains a vulnerability that permits unauthenticated attackers to perform the yp_option_update action without any CSRF token validation. An attacker can exploit this flaw by using the yp_remote_get function to gain administrative access to the affected WordPress installation.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.