CVE · High

CVE-2022-45374 — YARPP – Yet Another Related Posts Plugin [yet-another-related-posts-plugin] < 5.30.5 (closed)

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-45374 YARPP – Yet Another Related Posts Plugin [yet-another-related-posts-plugin] < 5.30.5 (closed) Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') High 7.7 < 5.30.5 5.30.5 2023-04-18

CVE-2022-45374

The YARPP plugin contains a local file inclusion vulnerability in versions through 5.30.4 where the yarpp shortcode fails to properly validate the template parameter, enabling users with subscriber access or higher to include and execute arbitrary files from the server. An attacker could leverage this flaw to run arbitrary PHP code, potentially bypassing security restrictions, accessing sensitive information, or executing malicious code through uploaded files that would normally be considered harmless. The vulnerability was resolved in version 5.30.5.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.