Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-73397: WordPress Youzify plugin <= 1.3.7: Malicious data can execute code

CVE-2026-73397 · published 1 month ago
Summary

The Youzify plugin for WordPress allows attackers to execute malicious code on a website if they can trick the plugin into processing untrusted data. This can happen if a website administrator uses an untrusted source to import plugin settings or data. To fix this, update the Youzify plugin to version 1.3.8 or later.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
youzify youzify <= 1.3.7
Original advisory text
Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions.
Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions.
Severity
9.8 Critical
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS <1%
Type
CWE-502Deserialization of Untrusted Data
Timeline
Published18 Aug 2026
Updated27 Sep 2026
First seen18 Aug 2026
Sources
CVE-2026-73397 · MITRE
Track software like this
Free during beta