PT-2015-5699 · Yoast · Wordpress Seo By Yoast

Ryan Dewhurst

·

Published

2015-03-17

·

Updated

2015-03-18

·

CVE-2015-2293

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions WordPress SEO by Yoast plugin versions prior to 1.5.7 WordPress SEO by Yoast plugin versions 1.6.x prior to 1.6.4 WordPress SEO by Yoast plugin versions 1.7.x prior to 1.7.4
Description The issue concerns multiple cross-site request forgery (CSRF) vulnerabilities in the WordPress SEO by Yoast plugin. These vulnerabilities allow remote attackers to hijack the authentication of certain users for requests that conduct SQL injection attacks. The order by and order parameters in the wpseo bulk-editor page are specifically vulnerable to such attacks.
Recommendations For WordPress SEO by Yoast plugin versions prior to 1.5.7, update to version 1.5.7 or later. For WordPress SEO by Yoast plugin versions 1.6.x prior to 1.6.4, update to version 1.6.4 or later. For WordPress SEO by Yoast plugin versions 1.7.x prior to 1.7.4, update to version 1.7.4 or later.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-2293

Affected Products

Wordpress Seo By Yoast