Wordfence reported this vulnerability to Yoast Tuesday May 3rd and their team has released a fix today, Friday May 6th. We recommend that you upgrade immediately if you are using Yoast SEO. This vulnerability is fixed in Yoast SEO version 3.2.5.
Details of the Vulnerability
Yoast SEO plugin has a Sensitive Data Exposure vulnerability. Plugin registers the following AJAX actions:
- wpseo_export
- get_focus_keyword_usage
- get_term_keyword_usage
This kind of information should be available only to users with administrative capabilities. To be more precise, to users that have the manage_options capability, because the plugin’s option pages require this capability by default.
Source: Wordfence Blog
No comments:
Post a Comment
Note: only a member of this blog may post a comment.