HomeDefault status
unaffected
Any version before 5.0.26
affected
Description
The YML for Yandex Market WordPress plugin before 5.0.26 is vulnerable to Remote Code Execution via the feed generation process.
Problem types
CWE-94 Improper Control of Generation of Code ('Code Injection')
Product status
Any version before 5.0.26
Credits
Alex Tselevich (nos3curity)
WPScan
References
wpscan.com/...rability/9bb1a4ca-976c-461d-82de-8a3b04a56fbc/