← back
CVE-2019-11886

CVE-2019-11886

EPSS 1.9%
Vexday Risk Score
18Low
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS EPSS 1.9%KEV nãoPoC Nuclei simMetasploit Patch
Lifecycle
13 May 2019Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
The WaspThemes Visual CSS Style Editor (aka yellow-pencil-visual-theme-customizer) plugin before 7.2.1 for WordPress allows yp_option_update CSRF, as demonstrated by use of yp_remote_get to obtain admin access.
Affected products
n/a · n/a

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →