HomeSecurityCritical vulnerability identified in the “WordPress SEO by Yoast” plugin

Critical vulnerability identified in the WordPress SEO by Yoast plugin

"WordPress SEO by Yoast": A critical vulnerability has been discovered in the most popular plugin for the WordPress, which puts tens of millions of websites at risk and makes them vulnerable to hacking attacks.

WordPress SEO by Yoast

The vulnerability affects most versions of "WordPress SEO by Yoast," which has more than 14 million downloads, and is one of the most popular plugins for optimizing WordPress websites for search engines.

The vulnerability in the plugin was discovered by Ryan Dewhurst, a researcher and creator of “WPScan,” a plugin for detecting WordPress vulnerabilities.

All versions of "WordPress SEO by Yoast" released before version 1.7.3.3 are vulnerable to Blind SQL Injection attacks, according to an advisory published a few days ago.

SQL Injection (SQLi) vulnerabilities are classified as critical, as they could lead to database breaches and the leakage of confidential information.

To successfully exploit this vulnerability, the attacker would need to gain Admin, Editor, or Author privileges, which they can achieve through social engineering, tricking the victim into visiting a specially crafted website hosting the exploit.

 

Plugin users are urged to upgrade immediately

The good news is that the vulnerability has been fixed in the latest version of the plugin (1.7.4) and all users who have an earlier version of "WordPress SEO by Yoast" installed should upgrade immediately.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS