CVE-2019-11886: Yellowpencil Visual Css Style Editor
High severity, CVSS 8.8. EPSS: 1.9% chance of exploitation in the next 30 days.
The WaspThemes Visual CSS Style Editor (aka yellow-pencil-visual-theme-customizer) plugin before 7.2.1 for WordPress allows yp_option_update CSRF, as demonstrated by use of yp_remote_get to obtain admin access.
Affected products
- Yellowpencil Visual Css Style Editor: before 7.2.1 (fixed in 7.2.1)
Published 2019-05-13. Last modified 2026-06-17.