Yoast SEO <= 9.1.0 - Race Condition to Remote Code Execution
2018-11-06 00:00
AnonymousStrategic Overview
StatusPatched in 9.2.0
Affected Version
<= 9.1.0CVSS6.6Medium
CVE
CVE-2018-19370Vulnerability Overview
A Race condition vulnerability in unzip_file in admin/import/class-import-settings.php in the Yoast SEO (wordpress-seo) plugin before 9.2.0 for WordPress allows an SEO Manager to perform command execution on the Operating System via a ZIP import.
Technical Analysis
REMEDIATION: Update to version 9.2.0, or a newer patched version --- IDENTIFIER: CWE-362 (Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')) The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C