Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Badconker

#51828of 53,624
4.3Total CVSS
Vulnerabilities · 1
PT-2015-3538
4.3
2015-06-17
Yoast · Wordpress Seo By Yoast · CVE-2012-6692
**Name of the Vulnerable Software and Affected Versions** WordPress SEO by Yoast plugin versions prior to 2.2 **Description** A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML via the `post title` parameter to "wp-admin/post-new.php". This is due to improper handling in the snippet preview functionality. **Recommendations** For WordPress SEO by Yoast plugin versions prior to 2.2, update to version 2.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the snippet preview functionality until the update is applied. Avoid using the `post title` parameter in the affected functionality until the issue is resolved.