← back
CVE-2019-11886observed exploitation

CVE-2019-11886

40Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 1.9%
from disclosure to weapon
Published on NVDMay 13
VulnCheckApr 11
exploitation probability
1.9%top 22% of all CVEs
observed exploitation
yesVulnCheck
The WaspThemes Visual CSS Style Editor (aka yellow-pencil-visual-theme-customizer) plugin before 7.2.1 for WordPress allows yp_option_update CSRF, as demonstrated by use of yp_remote_get to obtain admin access.
Affected products
n/a · n/a