CVE Database /
CVE-2022-45374
CVE · High
CVE-2022-45374 — YARPP – Yet Another Related Posts Plugin [yet-another-related-posts-plugin] < 5.30.5 (closed)
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2022-45374
|
YARPP – Yet Another Related Posts Plugin [yet-another-related-posts-plugin] < 5.30.5 (closed) |
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
High
7.7
|
< 5.30.5
|
5.30.5 |
2023-04-18 |
—
|
CVE-2022-45374
The YARPP plugin contains a local file inclusion vulnerability in versions through 5.30.4 where the yarpp shortcode fails to properly validate the template parameter, enabling users with subscriber access or higher to include and execute arbitrary files from the server. An attacker could leverage this flaw to run arbitrary PHP code, potentially bypassing security restrictions, accessing sensitive information, or executing malicious code through uploaded files that would normally be considered harmless. The vulnerability was resolved in version 5.30.5.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings