CVE · Medium

CVE-2018-19370 — Yoast SEO – Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 9.2.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2018-19370 Yoast SEO – Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 9.2.0 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') Medium 6.6 < 9.2.0 9.2.0 2018-11-06

CVE-2018-19370

The Yoast SEO plugin before version 9.2.0 contains a race condition in its unzip_file function within the settings import functionality that permits an SEO Manager to execute arbitrary operating system commands through the upload and processing of a crafted ZIP file.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.