"WordPress SEO by Yoast": A critical vulnerability has been discovered in the most popular plugin for the WordPress, which puts tens of millions of websites at risk and makes them vulnerable to hacking attacks.
The vulnerability affects most versions of "WordPress SEO by Yoast," which has more than 14 million downloads, and is one of the most popular plugins for optimizing WordPress websites for search engines.
The vulnerability in the plugin was discovered by Ryan Dewhurst, a researcher and creator of “WPScan,” a plugin for detecting WordPress vulnerabilities.
All versions of "WordPress SEO by Yoast" released before version 1.7.3.3 are vulnerable to Blind SQL Injection attacks, according to an advisory published a few days ago.
SQL Injection (SQLi) vulnerabilities are classified as critical, as they could lead to database breaches and the leakage of confidential information.
To successfully exploit this vulnerability, the attacker would need to gain Admin, Editor, or Author privileges, which they can achieve through social engineering, tricking the victim into visiting a specially crafted website hosting the exploit.
Plugin users are urged to upgrade immediately
The good news is that the vulnerability has been fixed in the latest version of the plugin (1.7.4) and all users who have an earlier version of "WordPress SEO by Yoast" installed should upgrade immediately.

