CVE-2018-19370

Published
View on NVD ↗
CVSS v3
N/A
CVSS v2
6
MEDIUM
Affected
2
PROJECTS

Description

A Race condition vulnerability in unzip_file in admin/import/class-import-settings.php in the Yoast SEO (wordpress-seo) plugin before 9.2.0 for WordPress allows an SEO Manager to perform command execution on the Operating System via a ZIP import.

<p>Improve your SEO with real-time feedback, schema, and clear guidance. Upgrade for AI tools, Google Docs integration, and 24/7 support, no hidden fees.</p> <h3>Yoast SEO: The #1 WordPress SEO Plugin</h3> <p>Since 2008, <strong>Yoast SEO</strong> has helped millions of websites worldwide improve their visibility and SEO performance.<br /> Our mission is <strong>SEO for Everyone</strong> — from small local businesses to some of the most visited sites on the web.</p> <p>Yoast SEO gives you everything you need to manage your on-site SEO effectively.<br /> The <a href="https://yoa.st/1v8" rel="nofollow ugc">Yoast SEO Premium</a> plugin and its extensions unlock even more advanced and AI-powered tools.</p> <h3>Handing you the competitive edge</h3> <p>SEO is the most consistent and cost-effective source of website traffic — but it can be complex. Whether you&#8217;re just starting out or an advanced user, Yoast SEO helps you handle SEO confidently and efficiently.</p> <p>Don&#8217;t have time to stay on top of AI search and best practices? Keeping Yoast SEO updated means you automatically benefit from ongoing technical improvements, schema updates, and AI advancements — all guided by our signature traffic light approach.</p> <p>Empower search engines to better understand your website using <strong>Schema.org structured data integration</strong>, and access in-depth content and readability analysis tools that help you create content designed to perform well in search.</p> <h3>Quick and easy setup</h3> <p>Setting up Yoast SEO is quick and straightforward — no technical background required.<br /> Our step-by-step configuration wizard walks you through essential setup details so Yoast SEO can generate accurate <strong>structured data</strong> that helps search engines understand your site.</p> <p>Switching from another SEO plugin like Rank Math or AIOSEO? Migration is seamless.<br /> Import your existing SEO data and settings safely with our built-in import/export tools.</p> <h3>Content and AI features</h3> <p>Unlock your content&#8217;s full potential with Yoast SEO&#8217;s <strong>advanced content analysis</strong> and <strong>AI-powered tools</strong>.</p> <p><strong>Content optimization features:</strong><br /> &#8211; Detailed <strong>SEO analysis</strong> to guide keyword targeting and site performance.<br /> &#8211; <strong>Readability analysis</strong> for clear, engaging, and user-friendly writing.<br /> &#8211; <strong>SERP previews</strong> for both desktop and mobile results.<br /> &#8211; <strong>HowTo and FAQ blocks</strong> with built-in schema support.<br /> &#8211; <strong>Breadcrumbs block</strong> for improved navigation.<br /> &#8211; <strong>Inclusive Language Analysis</strong> to make your content more considerate and accessible.<br /> &#8211; <strong>Semrush integration</strong> for keyword research directly in Yoast SEO.<br /> &#8211; <strong>Wincher integration</strong> to track keyword performance inside your dashboard.<br /> &#8211; <strong>Elementor integration</strong> for seamless optimization within your favorite builder.</p> <p><strong>AI features (included in Premium):</strong><br /> &#8211; <strong><a href="https://yoa.st/51c" rel="nofollow ugc">Yoast AI Generate</a></strong> – Instantly create five SEO-friendly titles and meta descriptions, with one-click regeneration for more options.<br /> &#8211; <strong>Yoast AI Optimize</strong> – Improve keyphrase placement (introduction, distribution, density) automatically.<br /> &#8211; <strong>Yoast AI Summarize</strong> <em>(New 2025)</em> – Generate quick content summaries for briefs or social posts.<br /> &#8211; <strong>All AI tools included</strong> – No extra accounts, limits, or hidden costs.</p> <p>These tools help you craft optimized, helpful content that resonates with readers and performs strongly across search platforms.</p> <h3>Taking care of your technical SEO</h3> <p>Yoast SEO automatically handles much of your site&#8217;s technical SEO, freeing you to focus on your content.</p> <p><strong>Key technical SEO features:</strong><br /> &#8211; Automated <strong>meta tag optimization</strong> right out of the box.<br /> &#8211; <strong>Canonical URLs</strong> to prevent duplicate content issues.<br /> &#8211; <strong>Advanced XML sitemaps</strong> for clear site indexing.<br /> &#8211; <strong>Best-in-class Schema.org integration</strong> to improve search understanding and appearance.<br /> &#8211; Complete <strong>breadcrumb control</strong> for visitors and crawlers.<br /> &#8211; <strong>Performance improvements</strong> that help reduce load times.<br /> &#8211; <strong>Crawl settings</strong> to manage how bots access your site and reduce environmental impact.<br /> &#8211; <strong>LLMs.txt management</strong> to guide how large language models interact with your content.</p> <p>Every update delivers ongoing technical SEO enhancements automatically.</p> <h3>Keep your website in perfect shape</h3> <p>Whether you&#8217;re a creator, business owner, or developer, Yoast SEO helps maintain your website&#8217;s SEO health:</p> <ul> <li><strong>Cornerstone content tools</strong> to organize and prioritize key pages.</li> <li><strong>Front-end SEO inspector</strong> to view and edit titles, descriptions, and schema live.</li> <li><strong>SEO roles</strong> to delegate plugin access securely across teams.</li> <li><strong>Regular 2-week update cycle</strong> to ensure compatibility with the latest SEO standards and search engine changes.</li> </ul> <h3>Powerful integrations</h3> <p>Yoast SEO works seamlessly with popular WordPress tools to enhance your workflow and results:</p> <ul> <li><strong><a href="https://en-gb.wordpress.org/plugins/google-site-kit/" rel="nofollow ugc">Google Site Kit</a>:</strong> Access insights from Search Console, Analytics, and PageSpeed directly inside WordPress.</li> <li><strong><a href="https://wordpress.org/plugins/advanced-custom-fields/" rel="ugc">Advanced Custom Fields (ACF)</a>:</strong> Combine with <a href="https://wordpress.org/plugins/acf-content-analysis-for-yoast-seo/" rel="ugc">ACF Content Analysis for Yoast SEO</a> for advanced field optimization.</li> <li><strong><a href="https://wordpress.org/plugins/elementor/" rel="ugc">Elementor</a>:</strong> Use full Yoast SEO functionality inside Elementor&#8217;s editor.</li> <li><strong><a href="https://wordpress.org/plugins/wp-search-with-algolia/" rel="ugc">Algolia</a>:</strong> Enhance internal search accuracy and performance.</li> <li><strong><a href="https://www.semrush.com/" rel="nofollow ugc">Semrush</a>:</strong> Discover and optimize for high-value keywords.</li> <li><strong><a href="https://wincher.com/" rel="nofollow ugc">Wincher</a>:</strong> Track keyword positions and trends in Google Search.</li> <li><strong><a href="https://wordpress.org/plugins/jetpack/" rel="ugc">Jetpack</a>:</strong> Manage SEO and social previews all in one place.</li> <li><strong><a href="https://en-gb.wordpress.org/plugins/easy-digital-downloads/" rel="nofollow ugc">Easy Digital Downloads (EDD)</a>:</strong> Improve digital product visibility with integrated schema.</li> <li><strong><a href="https://mastodon.social/" rel="nofollow ugc">Mastodon</a>:</strong> Verify your website on Mastodon with Yoast SEO Premium.</li> <li><strong><a href="https://en-gb.wordpress.org/plugins/woocommerce/" rel="nofollow ugc">WooCommerce</a>:</strong> Optimize ecommerce SEO with the dedicated WooCommerce extension.</li> </ul> <h3>Yoast SEO Premium – AI-powered SEO for WordPress</h3> <p><a href="https://yoa.st/1v8" rel="nofollow ugc">Yoast SEO Premium</a> enhances everything in Yoast SEO with advanced automation, AI tools, and professional support.<br /> Trusted by millions, it helps you optimize efficiently for both traditional and AI-driven search.</p> <p><strong>Tackle your SEO challenges:</strong><br /> &#8211; Keep pace with algorithm and AI search updates.<br /> &#8211; Target the right audience effectively.<br /> &#8211; Automate redirects, crawl controls, and internal linking.<br /> &#8211; Identify orphaned content and improve site structure.<br /> &#8211; Get support when you need it.</p> <p><strong>Premium highlights:</strong><br /> &#8211; AI-generated titles and meta descriptions.<br /> &#8211; Smart internal linking suggestions.<br /> &#8211; Social previews for Facebook and X.<br /> &#8211; <strong>Redirect Manager</strong> with bulk tools and automatic prompts.<br /> &#8211; <strong>Bot Blocker</strong> for AI crawlers (GPTBot, CCBot, Google-Extended).<br /> &#8211; <strong>IndexNow</strong> integration for fast content updates.<br /> &#8211; <strong>Front-end SEO Inspector</strong> for real-time editing.<br /> &#8211; <strong>SEO Workouts</strong> to improve orphaned and cornerstone content.<br /> &#8211; <a href="https://yoa.st/52u" rel="nofollow ugc"><strong>Google Docs add-on</strong></a> for seamless SEO writing in Docs.<br /> &#8211; <strong>24/7 premium support</strong> from SEO specialists.</p> <p><strong>Includes at no extra cost:</strong><br /> &#8211; <a href="https://yoa.st/1uu" rel="nofollow ugc">Yoast Local SEO</a>: Optimize for local audiences and Google Maps.<br /> &#8211; <a href="https://yoa.st/1uw" rel="nofollow ugc">Yoast Video SEO</a>: Ensure Google understands your videos with video sitemaps and schema.<br /> &#8211; <a href="https://yoa.st/1uv" rel="nofollow ugc">Yoast News SEO</a>: Increase visibility in Google News and Top Stories.</p> <h3>Yoast WooCommerce SEO – Advanced SEO for Online Stores</h3> <p><strong>Yoast WooCommerce SEO</strong> builds on Yoast SEO Premium with ecommerce-specific tools to improve your store&#8217;s visibility and conversion potential.</p> <p><strong>Key ecommerce SEO features:</strong><br /> &#8211; <strong>WooCommerce-specific XML sitemap</strong> excluding non-shopping content.<br /> &#8211; <strong>Product structured data</strong> for enhanced rich results (price, reviews, availability).<br /> &#8211; <strong>Canonical URL management</strong> to prevent duplicates.<br /> &#8211; <strong>Ecommerce-focused content analysis</strong> for GTINs, SKUs, and short descriptions.<br /> &#8211; <strong>AI Generate for ecommerce</strong> – Instantly create optimized titles and meta descriptions for product and category pages.</p> <p><strong>Benefits:</strong><br /> &#8211; Improve product visibility with automated structured data.<br /> &#8211; Enhance crawl efficiency for large catalogs.<br /> &#8211; Save time through metadata templates and automation.<br /> &#8211; Increase engagement with AI-optimized ecommerce metadata.</p> <p>Built for WooCommerce, trusted by thousands of online stores worldwide.</p> <h3>For Developers</h3> <p>Yoast SEO is built with developers in mind. With modern APIs, hooks, and a unified indexables system, you can extend or integrate SEO functionality across custom themes, plugins, or headless setups.</p> <h3>REST API</h3> <p>Retrieve SEO metadata for any post or URL, including meta tags, Open Graph, Twitter Cards, and Schema.org data.<br /> <a href="https://yoa.st/53l" rel="nofollow ugc">Learn more about the REST API</a>.</p> <h3>Surfaces API</h3> <p>Access SEO data directly in code via <code>YoastSEO()-&gt;meta-&gt;for_current_page()</code>.<br /> Supports titles, descriptions, canonicals, and schema.<br /> <a href="https://yoa.st/53m" rel="nofollow ugc">Read the Surfaces API documentation</a>.</p> <h3>Metadata API</h3> <p>Use the <a href="https://yoa.st/53n" rel="nofollow ugc">Metadata API</a> to filter, override, or extend meta tags with WordPress hooks such as <code>wpseo_title</code>, <code>wpseo_metadesc</code>, and <code>wpseo_canonical</code>.</p> <h3>Schema API</h3> <p>The <a href="https://yoa.st/53o" rel="nofollow ugc">Schema API</a> lets you modify or extend Schema.org graph pieces, including Article, Organization, Person, Breadcrumb, and WebPage entities.</p> <h3>Block Editor compatibility</h3> <p>Yoast SEO integrates directly with the WordPress Block Editor (Gutenberg).<br /> It outputs schema for HowTo and FAQ blocks by default, and developers can extend schema for custom blocks.</p> <h3>Indexables</h3> <p>At the core of Yoast SEO lies the <a href="https://yoa.st/53q" rel="nofollow ugc">indexables system</a>, unifying all SEO data for faster queries and consistent metadata across outputs.</p> <h3>Ongoing support and education</h3> <p>Yoast is powered by expert developers, testers, and SEO specialists who keep improving the plugin.<br /> We&#8217;re committed to helping users grow their SEO skills with resources such as:</p> <ul> <li><a href="https://yoa.st/3ri" rel="nofollow ugc">Yoast SEO Academy</a>: Free and premium SEO courses (included in all paid plans).</li> <li><a href="https://yoast.com/seo-blog/" rel="nofollow ugc">Yoast SEO blog</a>, newsletter, and webinars.</li> <li><a href="https://yoa.st/53i" rel="nofollow ugc">Yoast SEO Update podcast</a> for the latest SEO insights.</li> <li><a href="https://github.com/Yoast/wordpress-seo" rel="nofollow ugc">Bug reports on GitHub</a> (for issue tracking, not support).</li> </ul> <p><strong>Yoast SEO</strong> — built to make search optimization accessible, reliable, and ready for the future of AI search.</p>
WordPress Plugin DirectoryWordPress Plugin Directory
963M
Yoast SEO for WordPress
GitHubGitHub
1.96K