CVE-2023-28775: WordPress Yoast SEO Premium plugin <= 20.4 - Unauthenticated Zapier API Key Reset vulnerability
Published Jun 11, 2024
·Updated
Missing Authorization vulnerability in Yoast Yoast SEO Premium.This issue affects Yoast SEO Premium: from n/a through 20.4.
Affected Software
1 affected component
Yoast Yoast SEO WordPress<20.5
Remediation
Information
Update to 20.5 or a higher version.
Event History
Jun 11, 2024
CVE Published
via MITRE·09:16 AM
Data Sourced
via MITRE·09:16 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-28775?
CVE-2023-28775 is considered a critical missing authorization vulnerability affecting Yoast SEO Premium versions up to 20.4.
2
How do I fix CVE-2023-28775?
To fix CVE-2023-28775, upgrade Yoast SEO Premium to version 20.5 or later immediately.
3
What impact does CVE-2023-28775 have on my website?
CVE-2023-28775 allows unauthenticated users to reset the Zapier API key, potentially leading to unauthorized access and control.
4
Which versions of Yoast SEO Premium are affected by CVE-2023-28775?
CVE-2023-28775 affects Yoast SEO Premium from n/a through version 20.4.
5
Is CVE-2023-28775 being actively exploited?
There is currently no public information indicating that CVE-2023-28775 is being actively exploited, but it is advised to apply the patch promptly.