← WordPress Vulnerabilities
WordPress security by component

Simple Yearly Archive

Simple Yearly Archive is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Aug 05, 2026; the highest published CVSS base score is 6.4.

Plugin slug: simple-yearly-archive

CVE-2026-7441: Simple Yearly Archive posttype shortcode attribute permits stored XSS

Simple Yearly Archive through 2.2.4 lets a Contributor store an attacker-controlled posttype attribute in the SimpleYearlyArchive shortcode. The value is not sufficiently sanitized or escaped before page output, allowing stored JavaScript to execute for visitors to the injected page, including administrators. The CNA does not disclose the rendering function or exact HTML context.

PublishedAug 05, 2026
Known safe version> 2.2.4
Published vulnerabilities for simple-yearly-archive
Safe version
Aug 05, 2026 CVE-2026-7441
Simple Yearly Archive posttype shortcode attribute permits stored XSS
Simple Yearly Archive through 2.2.4 lets a Contributor store an attacker-controlled posttype attribute in the SimpleYearlyArchive shortcode. The value is not sufficiently sanitized or escaped before page output, allowing stored JavaScript to execute for visitors to the injected page, including administrators. The CNA does not disclose the rendering function or exact HTML context.
> 2.2.4
CVE6.4
NVDPending
Apr 25, 2023 CVE-2023-25484
Simple Yearly Archive: Cross-site scripting
Simple Yearly Archive is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE5.9
NVD4.8