--> Yoast WordPress SEO Plugin Makes Your Website Vulnerable! | Experience Lab - Online business creation and development guide for bloggers and startups

Yoast WordPress SEO Plugin Makes Your Website Vulnerable!

According to a latest news, the popular Yoast SEO WordPress Plugin has a major vulnerability that makes a website susceptible to blind SQL ...




According to a latest news, the popular Yoast SEO WordPress Plugin has a major vulnerability that makes a website susceptible to blind SQL injections. This is a very popular plugin that is used by over 14 million websites. Reportedly, all versions of SEO by Yoast prior to 1.7.3.3 are vulnerable to Blind SQL Injection web application flaw. This is an alarming news for those that use this plugin, because it could seriously compromise the data on their website.


According to Mohit Kumar of Hacker News:



“Basically in SQLi attack, an attacker inserts a malformed SQL query into an application via client-side input. However, in this scenario, an outside hacker can’t trigger this vulnerability itself because the flaw actually resides in the ‘admin/class-bulk-editor-list-table.php’ file, which is authorized to be accessed by WordPress Admin, Editor or Author privileged users only. 




Therefore, in order to successfully exploit this vulnerability, it is required to trigger the exploit from authorized users only. This can be achieved with the help of social engineering, where an attacker can trick authorized user to click on a specially crafted payload exploitable URL.”



So in other words, WordPress admins can be tricked into clicking on links that would then trigger an SQLi attack. After the attack, the attacker could then add their own admin account to the vulnerable WordPress site and do whatever they want with it.





Everyone who has SEO by Yoast installed is not going to be automatically affected by this. The attack can only be manually triggered by a WordPress admin, editor, or author who clicks on a dangerous link created by the attacker.





In addition, this is something that can easily fixed by updating your plugin to the latest version. The Yoast team promptly patched the exploit upon being notified, and the newest version (1.7.4) is said to fix the problem. The Premium version of the plugin has also been updated.


Security fix: fixed possible CSRF and blind SQL injection vulnerabilities in bulk editor. Added strict sanitation to order_by and order params. Added extra nonce checks on requests sending additional parameters. Minimal capability needed to access the bulk editor is now Editor. Thanks Ryan Dewhurst from WPScan for discovering and responsibly disclosing this issue.


In the future, you can have plugin updates taken care of automatically by going to the Manage > Plugins & Themes > Auto Updates tab. It is strongly recommended that you update all SEO and security plugins on your websites as soon as possible.





Stay safe!

COMMENTS

Name

Affiliate Marketing,12,Announcement,34,Bing,9,Bitcoin,38,blog,7,Blogger Resources,42,Blogger Templates,4,blogger tricks,156,Blogging ethics,70,Blogging tips,198,Bugs and Errors,34,Business,9,Copyright Violation,9,CSS and HTMLTricks,95,Designs,8,drop down menu,7,eBook,12,Email Marketing,7,Events,30,Facebook,30,Facebook tricks,49,Google,157,Google AdSense,42,Google Analytics,7,Google Plus,51,Google Plus Tricks,38,Guest Posts,112,home,2,How To,77,Internet,1,JSON Feeds,25,Kitchen Recipes,2,Label Based Sitemap Themes,1,Make Money Online,108,Marketing,16,MBT Blogger Templates,7,Menus,1,News,146,Pages,1,Posts,10,presentations,15,Responsive,10,Reviews,7,SEO,307,Settings,6,Shortcode,15,Sitemap Themes,1,Social Media,155,Technology,7,Templates,1,Tips,2,Tools,1,Traffic Tips,80,Video,19,Web Designing,62,web hosting,18,Webmaster Tools,97,Widgets,199,wordpress,26,
ltr
item
Experience Lab - Online business creation and development guide for bloggers and startups: Yoast WordPress SEO Plugin Makes Your Website Vulnerable!
Yoast WordPress SEO Plugin Makes Your Website Vulnerable!
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgpvuQjnGWU2X8MzyY29eLIQZ4ducEgZUaH20PIiqCPonPFDsnI15JUQDLw0jEQiuoN-U8Z-NntTdjmnAB2DJ8B26axODkfhKOH5JU466SlDnviVmlzn6Cyc8AXoSueDP4W3MqKhY2tIupI/s1600/yoast.png
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgpvuQjnGWU2X8MzyY29eLIQZ4ducEgZUaH20PIiqCPonPFDsnI15JUQDLw0jEQiuoN-U8Z-NntTdjmnAB2DJ8B26axODkfhKOH5JU466SlDnviVmlzn6Cyc8AXoSueDP4W3MqKhY2tIupI/s72-c/yoast.png
Experience Lab - Online business creation and development guide for bloggers and startups
https://www.experiencelab.info/2015/03/yoast-wordpress-seo-plugin-makes-your.html
https://www.experiencelab.info/
https://www.experiencelab.info/
https://www.experiencelab.info/2015/03/yoast-wordpress-seo-plugin-makes-your.html
true
2959477579779989044
UTF-8
Loaded All Posts Not found any posts VIEW ALL Readmore Reply Cancel reply Delete By Home PAGES POSTS View All RECOMMENDED FOR YOU LABEL ARCHIVE SEARCH ALL POSTS Not found any post match with your request Back Home Sunday Monday Tuesday Wednesday Thursday Friday Saturday Sun Mon Tue Wed Thu Fri Sat January February March April May June July August September October November December Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec just now 1 minute ago $$1$$ minutes ago 1 hour ago $$1$$ hours ago Yesterday $$1$$ days ago $$1$$ weeks ago more than 5 weeks ago Followers Follow THIS PREMIUM CONTENT IS LOCKED STEP 1: Share. STEP 2: Click the link you shared to unlock Copy All Code Select All Code All codes were copied to your clipboard Can not copy the codes / texts, please press [CTRL]+[C] (or CMD+C with Mac) to copy