534
VMScore

CVE-2018-19370

Published: 28/11/2018 Updated: 31/01/2019
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
CVSS v3 Base Score: 6.6 | Impact Score: 5.9 | Exploitability Score: 0.7
VMScore: 534
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

A Race condition vulnerability in unzip_file in admin/import/class-import-settings.php in the Yoast SEO (wordpress-seo) plugin prior to 9.2.0 for WordPress allows an SEO Manager to perform command execution on the Operating System via a ZIP import.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

yoast yoast seo