CVE-2015-2293: SQL Injection
Multiple cross-site request forgery (CSRF) vulnerabilities in admin/class-bulk-editor-list-table.php in the WordPress SEO by Yoast plugin before 1.5.7, 1.6.x before 1.6.4, and 1.7.x before 1.7.4 for WordPress allow remote attackers to hijack the authentication of certain users for requests that conduct SQL injection attacks via the (1) orderby or (2) order parameter in the wpseobulk-editor page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2293?
CVE-2015-2293 is considered a moderate severity vulnerability due to its potential impact on user authentication.
How do I fix CVE-2015-2293?
To fix CVE-2015-2293, update the Yoast SEO plugin to version 1.5.7 or later.
What versions of Yoast SEO are affected by CVE-2015-2293?
CVE-2015-2293 affects Yoast SEO versions before 1.5.7, as well as all versions 1.6.x before 1.6.4 and 1.7.x before 1.7.4.
What type of vulnerability is CVE-2015-2293?
CVE-2015-2293 is classified as a cross-site request forgery (CSRF) vulnerability.
Can CVE-2015-2293 lead to unauthorized actions?
Yes, CVE-2015-2293 can allow remote attackers to hijack user authentication and perform unauthorized actions.