Stored Cross-Site Scripting in Youzify Plugin for WordPress
CVE-2026-1559
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 18 April 2026
What is CVE-2026-1559?
The Youzify plugin for WordPress, utilized in social networking functionalities, suffers from a Stored Cross-Site Scripting vulnerability through the 'checkin_place_id' parameter. This issue arises due to a lack of proper input sanitization and output escaping in all versions up to and including 1.3.6. Authenticated attackers with Subscriber-level access or higher can exploit this vulnerability to inject malicious web scripts. These scripts may execute whenever a user accesses a compromised page, potentially leading to unauthorized actions or data exposure.
Affected Version(s)
Youzify β BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress 0 <= 1.3.6