CVE-2019-11886: Yellowpencil Visual Css Style Editor

High severity, CVSS 8.8. EPSS: 1.9% chance of exploitation in the next 30 days.

The WaspThemes Visual CSS Style Editor (aka yellow-pencil-visual-theme-customizer) plugin before 7.2.1 for WordPress allows yp_option_update CSRF, as demonstrated by use of yp_remote_get to obtain admin access.

Affected products

  • Yellowpencil Visual Css Style Editor: before 7.2.1 (fixed in 7.2.1)

Published 2019-05-13. Last modified 2026-06-17.