medium·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2019-11869 Scanner

CVE-2019-11869 scanner - Cross-Site Scripting (XSS) vulnerability in Yuzo Related Posts plugin for Wordpress

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2019-11869
6.1
CVSS

The Yuzo Related Posts plugin 5.12.94 for WordPress has XSS because it mistakenly expects that is_admin() verifies that the request comes from an admin user (it actually only verifies that the request is for an admin page). An unauthenticated attacker can inject a payload into the plugin settings, such as the yuzo_related_post_css_and_style setting.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

The Yuzo Related Posts plugin is a popular WordPress plugin that helps website owners display related posts to their visitors. With over 60,000 active installations, this plugin is widely used to improve user engagement by suggesting related content to readers. Typically, website owners use this plugin to keep visitors engaged with their website content and drive traffic to their pages.

However, the Yuzo Related Posts plugin was recently found to have a serious security vulnerability code CVE-2019-11869. This vulnerability arises from the plugin mistakenly expecting that requests come from administrative users when is_admin() function is called. Unfortunately, the is_admin() function only checks if the requested page is an admin page, which leaves the plugin open to cross-site scripting (XSS) attacks.

When an attacker exploits this vulnerability, they can inject malicious code into the plugin settings. This malicious code will then be executed whenever a user accesses the settings page, potentially allowing the attacker to compromise user data or even take over the website. The exploit also exposes the website to further attacks, making it vulnerable to other types of hacker attacks.

In conclusion, the Yuzo Related Posts plugin for WordPress is a popular tool for improving user engagement on websites that can be vulnerable to cyber attacks. It's important for website owners to stay vigilant and take appropriate measures to keep their websites safe. By using a reliable security tool like s4e.io, website owners can stay updated on the latest vulnerabilities and take immediate action to protect their digital assets.

 

REFERENCES

Solution Advice

To protect against this vulnerability, website owners should take adequate security measures, such as:

  • Update the Yuzo Related Posts plugin to the latest version as soon as possible.
  • Restrict access to the plugin settings page only to authorized users.
  • Regularly scan your website for vulnerabilities by using reliable security tools.
  • Use a web application firewall to protect your website from attacks.
  • Regularly change your login credentials, including passwords and usernames, to strengthen your website's security.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2019-11869 scanner - Cross-Site Scripting (XSS) vulnerability in Yuzo Related Posts plugin for Wordpress S4E