WordPress security by component
Simple Yearly Archive
Plugin description
Simple Yearly Archive is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Aug 05, 2026; the highest published CVSS base score is 6.4.
Plugin slug:
simple-yearly-archiveLatest vulnerability
CVE-2026-7441: Simple Yearly Archive posttype shortcode attribute permits stored XSS
Simple Yearly Archive through 2.2.4 lets a Contributor store an attacker-controlled posttype attribute in the SimpleYearlyArchive shortcode. The value is not sufficiently sanitized or escaped before page output, allowing stored JavaScript to execute for visitors to the injected page, including administrators. The CNA does not disclose the rendering function or exact HTML context.
| Safe version |
|
||
|---|---|---|---|
| Aug 05, 2026 |
CVE-2026-7441
Simple Yearly Archive posttype shortcode attribute permits stored XSS
Simple Yearly Archive through 2.2.4 lets a Contributor store an attacker-controlled posttype attribute in the SimpleYearlyArchive shortcode. The value is not sufficiently sanitized or escaped before page output, allowing stored JavaScript to execute for visitors to the injected page, including administrators. The CNA does not disclose the rendering function or exact HTML context.
|
> 2.2.4 |
CVE6.4
NVDPending
|
| Apr 25, 2023 |
CVE-2023-25484
Simple Yearly Archive: Cross-site scripting
Simple Yearly Archive is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE5.9
NVD4.8
|