Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2019-11869 PoC — WordPress Yuzo Related Posts插件跨站脚本漏洞

Source
Associated Vulnerability
Title:WordPress Yuzo Related Posts插件跨站脚本漏洞 (CVE-2019-11869)
Description:The Yuzo Related Posts plugin 5.12.94 for WordPress has XSS because it mistakenly expects that is_admin() verifies that the request comes from an admin user (it actually only verifies that the request is for an admin page). An unauthenticated attacker can inject a payload into the plugin settings, such as the yuzo_related_post_css_and_style setting.
Readme
# CVE-2019-11869
File Snapshot

[4.0K] /data/pocs/135fd5603fe69c3892761ebbca853d39be6f7986 ├── [ 20] cve-2019-11869.yaml ├── [2.5K] main.go └── [ 16] README.md 0 directories, 3 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →