PT-2026-33579 · WordPress · Youzify

·

CVE-2026-1559

·

Published

2026-04-18

·

Updated

2026-04-18

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Youzify versions prior to 1.3.7
Description The Youzify plugin for WordPress contains a Stored Cross-Site Scripting issue caused by insufficient input sanitization and output escaping. Authenticated attackers with Subscriber-level access or higher can inject arbitrary web scripts through the checkin place id parameter. These scripts execute whenever a user visits the affected page.
Recommendations Update the plugin to a version later than 1.3.6. As a temporary workaround, restrict the use of the checkin place id parameter to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-1559

Affected Products

Youzify