CVE · Medium

CVE-2023-28775 — Yoast SEO Premium [wordpress-seo-premium] < 20.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-28775 Yoast SEO Premium [wordpress-seo-premium] < 20.5 Missing Authorization Medium 5.3 < 20.5 20.5 2023-05-09

CVE-2023-28775

The Yoast SEO Premium plugin for WordPress contains a flaw in versions 20.4 and earlier where an unauthenticated attacker can modify the Zapier API Key connection because the plugin fails to verify user capabilities before processing the request. This vulnerability allows unprivileged users to disconnect the integration without proper authorization checks. The issue was resolved in version 20.5 and later.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.