CVE-2026-1559

Basic Information

Severity MEDIUM
Base Score 6.4
CNA Wordfence
Published Date 2026-04-17 21:26:05 UTC
Last Modified 2026-04-17 21:26:05 UTC
CVE.org Link https://www.cve.org/CVERecord?id=CVE-2026-1559
NVD https://nvd.nist.gov/vuln/detail/CVE-2026-1559

Description

The Youzify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'checkin_place_id' parameter in all versions up to, and including, 1.3.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Affected Products

Vendor Product
youzify youzify – buddypress community, user profile, social network & membership plugin for wordpress