WordPress Yoast SEO Premium Plugin <= 20.4 is vulnerable to Broken Access Control

holms

Active member
Elite
XNullUser
Joined
May 7, 2021
Messages
170
Reaction score
183
Points
43
NullCash
530

WordPress Yoast SEO Premium Plugin <= 20.4 is vulnerable to Broken Access Control

xXoLkUF.jpg


The Yoast SEO Premium plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in versions up to, and including, 20.4. This makes it possible for unauthenticated attackers to disconnect a Zapier API Key.
Update to version 20.5 or 20.7
 
Top