Vulnerability Bulletins

Zero-Day Vulnerability in Yellow Pencil Visual Theme Customizer Exploited in the Wild


System information

   
Affected software Wordpress

Description

https://www.wordfence.com/blog/2019/04/zero-day-vulnerability-in-yellow-pencil-visual-theme-customizer-exploited-in-the-wild/ On Monday the WordPress plugin Yellow Pencil Visual Theme Customizer was closed in the WordPress.org plugin repository. The plugin is quite popular, with an active install base of over 30,000 websites. On Tuesday a security researcher made the irresponsible and dangerous decision to publish a blog post including a proof of concept (POC) detailing […]

More info:

https://www.wordfence.com/blog/2019/04/zero-day-vulnerability-in-yellow-pencil-visual-theme-customizer-exploited-in-the-wild/

Standar resources

Property Value
CVE

Version history

Version Comments Date
1.0 Advisory issued 2019-04-13
Ministerio de Defensa
CNI
CCN
CCN-CERT