High severity8.8NVD Advisory· Published May 13, 2019· Updated Jun 17, 2026
CVE-2019-11886
CVE-2019-11886
Description
The WaspThemes Visual CSS Style Editor (aka yellow-pencil-visual-theme-customizer) plugin before 7.2.1 for WordPress allows yp_option_update CSRF, as demonstrated by use of yp_remote_get to obtain admin access.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:yellowpencil:visual_css_style_editor:*:*:*:*:*:wordpress:*:*Range: <7.2.1
- WaspThemes/Visual CSS Style Editordescription
- Range: <7.2.1
Patches
Vulnerability mechanics
References
4- www.wordfence.com/blog/2019/04/zero-day-vulnerability-in-yellow-pencil-visual-theme-customizer-exploited-in-the-wild/nvdExploitThird Party Advisory
- wordpress.org/plugins/yellow-pencil-visual-theme-customizer/nvdRelease NotesThird Party Advisory
- wpvulndb.com/vulnerabilities/9256nvd
- www.pluginvulnerabilities.com/2019/04/09/recently-closed-visual-css-style-editor-wordpress-plugin-contains-privilege-escalation-vulnerability-that-leads-to-option-update-vulnerability/nvd
News mentions
0No linked articles in our index yet.