CVE Database /
CVE-2019-11886
CVE · High
CVE-2019-11886 — Visual CSS Style Editor [yellow-pencil-visual-theme-customizer] < 7.2.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2019-11886
|
Visual CSS Style Editor [yellow-pencil-visual-theme-customizer] < 7.2.1 |
Cross-Site Request Forgery (CSRF) |
High
8.8
|
< 7.2.1
|
7.2.1 |
2019-04-11 |
—
|
CVE-2019-11886
The Visual CSS Style Editor plugin for WordPress versions before 7.2.1 contains a vulnerability that permits unauthenticated attackers to perform the yp_option_update action without any CSRF token validation. An attacker can exploit this flaw by using the yp_remote_get function to gain administrative access to the affected WordPress installation.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings