Path Traversal Vulnerability in YML for Yandex Market by Yandex
CVE-2026-32567

6.8MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
25 March 2026

What is CVE-2026-32567?

The YML for Yandex Market plugin suffers from a Path Traversal vulnerability that allows attackers to access restricted directories through manipulated file paths. This issue affects versions below 5.3.0, potentially enabling unauthorized file deletion and other malicious activities. It's crucial for users to ensure they are running the latest version of the plugin to mitigate risks associated with this vulnerability.

Affected Version(s)

YML for Yandex Market <= n/a

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Ba Khanh | Patchstack Bug Bounty Program
.