Vulnerability record · CVE-2024-43919 · published 1 November 2024
CVE-2024-43919: YARPP WordPress plugin missing authorization access control flaw
Yarpp · Yet Another Related Posts Plugin
YARPP (Yet Another Related Posts Plugin) for WordPress contains a missing authorization vulnerability (CWE-862) affecting versions through 5.30.10. A function lacks an authorization check, letting an unauthenticated network attacker reach privileged functionality. With a CVSS base score of 9.8, this is a critical access control failure in a widely deployed WordPress plugin.
Description
Access Control vulnerability in YARPP YARPP allows . This issue affects YARPP: from n/a through 5.30.10.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication and no user interaction, plus a high EPSS percentile, makes this a critical exposure for any site running the affected plugin.
What it is
YARPP (Yet Another Related Posts Plugin) for WordPress contains a missing authorization vulnerability (CWE-862) affecting versions through 5.30.10. A function lacks an authorization check, letting an unauthenticated network attacker reach privileged functionality. With a CVSS base score of 9.8, this is a critical access control failure in a widely deployed WordPress plugin.
Impact
An attacker can invoke functionality that should require authorization, potentially gaining high confidentiality, integrity and availability impact on the affected WordPress site. The exact privileged action exposed is not detailed in the record, so the concrete outcome cannot be confirmed from the supplied facts.
Attack surface
Reachable over the network via HTTP with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The record does not specify the exact endpoint or parameter involved.
Exploitation
No CISA KEV listing and no ransomware association are recorded. EPSS is 0.44896 (98.7th percentile), indicating a high modeled probability of exploitation activity, but the only reference is a third-party advisory with no exploit tag.
What to do
- Update YARPP to a version later than 5.30.10 once the vendor releases a fix; the record does not name a patched version.
- If no fixed version is available, disable or remove the YARPP plugin until an update is published.
- Add a web application firewall rule or virtual patch blocking unauthenticated requests to the plugin's endpoints.
- Review WordPress user roles and plugin settings to confirm no unintended privileged functionality is exposed.
- Monitor vendor and Patchstack advisories for a confirmed patched release.
Detection
- Audit web server logs for unauthenticated requests to YARPP plugin paths, especially POST or admin-ajax calls.
- Alert on unexpected changes to WordPress options, posts or plugin settings originating from unauthenticated sessions.
- Correlate plugin endpoint access with subsequent administrative actions or content modifications.
- Watch for scanning or enumeration traffic targeting the YARPP plugin directory.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://patchstack.com/database/vulnerability/yet-another-related-posts-plugin/wordpress-yet-another-related-posts-plugi | Third Party Advisory |
Track CVE-2024-43919 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-43919), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.