CVE-2015-2293
The Yoast SEO plugin through version 1.7.3.3 contains blind SQL injection flaws in its bulk editor functionality, where the orderby and order parameters are inadequately filtered before inclusion in database queries despite using esc_sql(). Authenticated users with admin, editor, or author privileges can be tricked into clicking malicious links that execute arbitrary SQL commands, potentially allowing attackers to create new administrative accounts and fully compromise a WordPress site. The vulnerability was discovered on March 10, 2015 and patched in version 1.7.4 released the following day. The flaw carries a CVSS score of 9.0 due to its high impact on confidentiality, integrity, and availability despite requiring authentication.
Based on public CVE data (MITRE/NVD).