CVE

CVE-2015-2292 — Yoast SEO – Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 1.7.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2015-2292, CVE-2015-2293 Yoast SEO – Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 1.7.4 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Unknown < 1.7.4 1.7.4 2015-03-11

CVE-2015-2292, CVE-2015-2293

The WordPress SEO by Yoast plugin before version 1.5.7, 1.6.4, and 1.7.4 contained SQL injection flaws in the bulk editor functionality that allowed authenticated users to inject arbitrary SQL through the order_by and order parameters. These vulnerabilities could be exploited via cross-site request forgery to enable unauthenticated attackers to execute arbitrary database commands without needing direct access to the application.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.