MEDIUM (6.7)
    Plugin

    Stored Cross-Site Scripting Vulnerability in Youzify Plugin

    Published Date: 4/18/2026
    CVE ID: CVE-2026-1559

    Summary

    The Youzify plugin for WordPress contains a Stored Cross-Site Scripting (XSS) vulnerability via the 'checkin_place_id' parameter, affecting versions up to 1.3.6. This flaw allows authenticated users with Subscriber-level access or higher to inject malicious scripts that automatically execute when a page containing the script is accessed.

    Vulnerability Details

    This vulnerability arises from the Youzify plugin's inadequate sanitization and escaping of user input within the 'checkin_place_id' parameter. Since this parameter does not properly handle special characters or malicious scripts, attackers can store JavaScript code within the parameter. Once stored, this code executes in the browser of any user who visits the compromised page, potentially leading to session hijacking, defacement, or redirection to malicious websites. Although an attacker must have at least Subscriber-level access, this level of access is common and poses a significant risk if user roles are not properly managed. The vulnerability's impact can be critical, especially in environments with multiple subscriber-level users, since the stored script affects all who view the affected page. Proper input validation and output escaping practices are necessary to prevent such exploitation.

    Recommendations

    Users should implement stricter role management to limit the number of users with posting permissions and ensure that only trusted individuals have subscriber-level or higher access. Additionally, implementing a security plugin that provides XSS protection can help mitigate potential attacks in the short term. Monitoring site traffic for unusual activity may also assist in identifying and mitigating attacks quickly.

    Available Fixes

    Last Updated: 4/19/2026
    Jedar

    Jedar for Digital Rights is a non-profit organization dedicated to protecting digital freedoms, enhancing online privacy, and promoting secure digital practices for vulnerable communities worldwide.

    Follow Us

    All Rights Reserved © 2026 Jedar for Digital Rights.

    Cookie Preferences

    We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies.

    Learn More