← Vulnerability feed

Vulnerability record · CVE-2024-43919 · published 1 November 2024

CVE-2024-43919: YARPP WordPress plugin missing authorization access control flaw

Yarpp · Yet Another Related Posts Plugin

YARPP (Yet Another Related Posts Plugin) for WordPress contains a missing authorization vulnerability (CWE-862) affecting versions through 5.30.10. A function lacks an authorization check, letting an unauthenticated network attacker reach privileged functionality. With a CVSS base score of 9.8, this is a critical access control failure in a widely deployed WordPress plugin.

9.8 CVSS 3.1 Critical EPSS 45% · top 1.3% CWE-862 · Missing authorization
9.8CVSS 3.1 base score
45%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Access Control vulnerability in YARPP YARPP allows . This issue affects YARPP: from n/a through 5.30.10.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with network reachability, no authentication and no user interaction, plus a high EPSS percentile, makes this a critical exposure for any site running the affected plugin.

What it is

YARPP (Yet Another Related Posts Plugin) for WordPress contains a missing authorization vulnerability (CWE-862) affecting versions through 5.30.10. A function lacks an authorization check, letting an unauthenticated network attacker reach privileged functionality. With a CVSS base score of 9.8, this is a critical access control failure in a widely deployed WordPress plugin.

Impact

An attacker can invoke functionality that should require authorization, potentially gaining high confidentiality, integrity and availability impact on the affected WordPress site. The exact privileged action exposed is not detailed in the record, so the concrete outcome cannot be confirmed from the supplied facts.

Attack surface

Reachable over the network via HTTP with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The record does not specify the exact endpoint or parameter involved.

Exploitation

No CISA KEV listing and no ransomware association are recorded. EPSS is 0.44896 (98.7th percentile), indicating a high modeled probability of exploitation activity, but the only reference is a third-party advisory with no exploit tag.

What to do

  • Update YARPP to a version later than 5.30.10 once the vendor releases a fix; the record does not name a patched version.
  • If no fixed version is available, disable or remove the YARPP plugin until an update is published.
  • Add a web application firewall rule or virtual patch blocking unauthenticated requests to the plugin's endpoints.
  • Review WordPress user roles and plugin settings to confirm no unintended privileged functionality is exposed.
  • Monitor vendor and Patchstack advisories for a confirmed patched release.

Detection

  • Audit web server logs for unauthenticated requests to YARPP plugin paths, especially POST or admin-ajax calls.
  • Alert on unexpected changes to WordPress options, posts or plugin settings originating from unauthenticated sessions.
  • Correlate plugin endpoint access with subsequent administrative actions or content modifications.
  • Watch for scanning or enumeration traffic targeting the YARPP plugin directory.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-43919 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2023-0579Yarpp yet another related posts plugin sql injection vulnerabilityThe YARPP WordPress plugin before 5.30.3 does not validate and escape some of its shortcode attributes before using them in SQL statement/s, which co…EPSS 0.94%6.5CVE-2022-45374Yarpp yet another related posts plugin path traversal vulnerabilityImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in YARPP allows PHP Local File Inclusion.This issue affe…EPSS 0.84%5.4CVE-2023-2433Yarpp yet another related posts plugin cross-site scripting vulnerabilityThe YARPP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'className' parameter in versions up to, and including, 5.30.3 due to…EPSS 0.51%5.4CVE-2022-4471Yarpp yet another related posts plugin vulnerabilityThe YARPP WordPress plugin before 5.30.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post whe…EPSS 0.71%4.8CVE-2023-6495Yarpp yet another related posts plugin cross-site scripting vulnerabilityThe YARPP – Yet Another Related Posts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up …EPSS 0.26%4.0CVE-2024-0602Yarpp yet another related posts plugin cross-site scripting vulnerabilityThe YARPP – Yet Another Related Posts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up …EPSS 0.51%9.9CVE-2026-84869ScreenConnect client allows unauthorized file transfer and execution in remote sessionsA flaw in the ConnectWise ScreenConnect client lets files be transferred and executed inside an active remote session without authorization or Host c…KEVEPSS 0.92%analysed7.8CVE-2022-0492Linux kernel cgroups v1 release_agent privilege escalation and container escapeThe Linux kernel's cgroup_release_agent_write in kernel/cgroup/cgroup-v1.c mishandles authorization, letting the cgroups v1 release_agent feature be …KEVEPSS 5.5%analysed

Source: NIST National Vulnerability Database (record CVE-2024-43919), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.