CVE-2018-19370: Race Condition
Published Nov 28, 2018
·Updated
A Race condition vulnerability in unzipfile in admin/import/class-import-settings.php in the Yoast SEO (wordpress-seo) plugin before 9.2.0 for WordPress allows an SEO Manager to perform command execution on the Operating System via a ZIP import.
Affected Software
1 affected component
Yoast Yoast SEO WordPress<=9.2.0
Event History
Nov 28, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-19370?
CVE-2018-19370 is a race condition vulnerability in the Yoast SEO plugin for WordPress, allowing command execution on the operating system via a ZIP import.
2
What software versions are affected by CVE-2018-19370?
Yoast SEO plugin versions up to and including 9.2.0.
3
What is the severity of CVE-2018-19370?
CVE-2018-19370 has a severity rating of medium (6.6).
4
How do I fix CVE-2018-19370?
To fix CVE-2018-19370, update the Yoast SEO plugin to version 9.2.1 or later.
5
Where can I find more information about CVE-2018-19370?
You can find more information about CVE-2018-19370 on the Yoast SEO GitHub repository, the WordPress plugin page, and a YouTube video discussing the vulnerability.