PT-2026-33579 · WordPress · Youzify
Tharadol Suksamran
·
Published
2026-04-18
·
Updated
2026-04-18
·
CVE-2026-1559
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Youzify versions prior to 1.3.7
Description
The Youzify plugin for WordPress contains a Stored Cross-Site Scripting issue caused by insufficient input sanitization and output escaping. Authenticated attackers with Subscriber-level access or higher can inject arbitrary web scripts through the
checkin place id parameter. These scripts execute whenever a user visits the affected page.Recommendations
Update the plugin to a version later than 1.3.6.
As a temporary workaround, restrict the use of the
checkin place id parameter to minimize the risk of exploitation.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Youzify