S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Dec 3, 2024

CVE-2024-43919 Scanner

CVE-2024-43919 Scanner - Missing Authorization vulnerability in Yet Another Related Posts Plugin

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.7k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-43919
5.3
CVSSmedium
Exploitable remotely over the internet · no authentication required.

Access Control vulnerability in YARPP YARPP allows . This issue affects YARPP: from n/a through 5.30.10.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
YARPPby YARPP
n/a
yarppby yarpp
0
Updated Sep 10, 2026View on NVD →
Detail

The Yet Another Related Posts Plugin (YARPP) is a WordPress plugin used to display related posts on websites. It is primarily utilized by WordPress site administrators to enhance user engagement by showcasing similar content. The plugin supports various display types, providing customizable options for site owners.

The vulnerability detected in this plugin is Missing Authorization, allowing unauthenticated attackers to set display types via a missing capability check in the `yarpp_pro_set_display_types.php` file. This issue impacts versions up to and including 5.30.10.

Attackers exploit this vulnerability by sending crafted HTTP GET requests to the vulnerable endpoint, bypassing authentication checks. The affected parameter is improperly validated, allowing arbitrary modifications.

If exploited, this vulnerability may enable unauthorized changes to the website's display settings, leading to potential disruption of user experience or injection of malicious content. It also opens the possibility of other unauthorized actions on the website.

REFERENCES

Solution Advice
  • Update the plugin to a secure version where this vulnerability is patched.
  • Restrict access to the vulnerable file using server-level access controls.
  • Audit WordPress plugins regularly to identify outdated or vulnerable components.
  • Enable robust logging to detect unauthorized access attempts promptly.
  • Apply role-based access controls to limit user permissions.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.