WP Engine

Solutions
AgencyEnterpriseSmall & Medium BusinessMarketer
How WP Engine supports marketers.Benefits for marketers.Features that help you innovate.
Developer
How WP Engine supports developers.Benefits for developers.Features that help you move faster.
Explore Our Platform
Insights
Thought LeadershipTopics

Read articles, trends, and insights on these topics from leaders in marketing and technology.

Creative AgilityEnterprise PerformanceActionable IntelligenceEcosystem Integration
Resources

Access ebooks, whitepapers, webinars, and other knowledge from our ecosystem of digital experts.
Visit Resource Center.

Delivering a Slam Dunk Experience on WordPressEbook: The Ultimate Guide to WordPress Plugins15 Common WordPress Mistakes Agencies and their Clients Make
Case Studies
About
Our CompanyOur PlatformLatest News

Access the latest news from inside WP Engine.
Visit the Newsroom.

WP Engine Secures Strategic Growth Investment From Silver LakeWP Engine Unveils First WordPress Digital ExperienceWP Engine Expands Global Presence with New Office in Brisbane
Media Center

Get announcements and resources about WP Engine.

Press Releases
Careers at WP Engine
Pricing
Sales Questions?

Contact Sales

Discover why organizations of all types and sizes choose WP Engine — and how it can benefit you.

Chat

1

I'm available right now to answer any of your questions!

Reply

Call

+1-512-201-4819

Contact

Send a message

Compare Plans
Need Support?
Support DocumentationBilling HelpSupport

We offer support 24 hours a day, 7 days a week, 365 days a year. Log in to get expert one-on-one help.

Log in for support

Sales Questions

Contact Sales

Discover why organizations of all types and sizes choose WP Engine — and how it can benefit you.

Chat

1

I'm available right now to answer any of your questions!

Reply

Call

+1-512-201-4819

Contact

Send a message

Sign in
Sign in
Search

Search

Compare Plans
Call Sales +1-512-201-4819
Menu
AgencyEnterpriseSmall & Medium BusinessMarketers
How WP Engine supports marketers.Benefits for marketersFeatures that help you innovate.
Developers
How WP Engine supports developers.Benefits for developers.Features that help you move faster.
Our PlatformPricingResource CenterOur CompanySolution CenterThought LeadershipDocumentationCareers

Please Update The WordPress SEO By Yoast Plugin

Dustin Meza 3.11.2015

At WP Engine, we take the security of your sites very seriously, and we strive to keep you aware of any potential issues or vulnerabilities that could impact the sites you entrust to us.

We want take this opportunity to inform you that a critical security update has been made available for the WordPress SEO by Yoast plugin, which a portion of our customers use to improve search engine results. The update follows the discovery of a security flaw in the old version of the plugin could that allow authenticated individuals to perform Cross-Site Request Forgery (CSRF) and blind SQL injection using the bulk editor.

Due to the severity of the exploit, we’re asking our customers to update your WordPress SEO by Yoast plugin to the most recent version, which is available now via the Updates menu within your WordPress dashboard. And please make sure to run a backup of your site first. You can read more on how to perform a backup here: http://wpengine.com/support/restore/. We’ve emailed our affected customers, but wanted to post this information to our blog as well.

If you have any questions about updating your plugin or performing a backup please feel free to reach out to your WP Engine Support team at any time.

 

More WordPress news from WP Engine

Gear Up For SXSW Interactive With WP EngineATX Startup Crawl Ushers In SXSW Interactive

Comments

  1. thomas says

    March 12, 2015 at 3:32 am

    Hey !
    there is no new version available (the current is 1.7.4).
    The vulnerabilities affects oldest versions ?

    Thanks

    Reply
    • thomas says

      March 12, 2015 at 3:37 am

      woops i read too fast…

      Reply
  2. toby says

    March 12, 2015 at 4:09 am

    Why isn’t WP Engine proactively either updating the plugin or issuing a server patch like some other hosting companies are doing?

    Reply
    • Dustin Meza says

      March 12, 2015 at 10:10 am

      Hello Toby,

      Great question, we had a long discussion around this and as the vulnerability is limited to access from the admin, we felt that upgrading the plugin automatically, which for some sites had the potential to break their site, was not necessary at this time. We have done this in the past, and will continue to keep it as an option in the future.

      Reply

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

  • Subscribe

    Subscribe to our blog to get great tips for your WordPress site.

  • Favorite Tweets by @wpengine
  • Sign In

    Solutions

    • Agency
    • Enterprise
    • SMB
    • Marketer
    • Developer

    Insights

    • Blog
    • Torque
    • Velocitize

    About

    • Our Company
    • Leadership Team
    • Our Platform
    • Careers
    • Affiliates
    • Contact
    • Legal
    • Newsroom
    • Privacy Policy

    Resources

    • Resource Center
    • Documentation
    • Solution Center
    • Find an Agency

    WP Engine

    504 Lavaca Street, Suite 1000
    Austin, TX 78701

    Sales

    +1-512-201-4819
    [email protected]
    7am–7pm CST

    Billing

    [email protected]

    • Facebook
    • Twitter
    • LinkedIn
    • YouTube
    • Instagram
    • RSS
    © 2013—2025 WPEngine, Inc. All rights reserved.
    WP ENGINE®, VELOCITIZE®, TORQUE®, EVERCACHE®, and the cog logo service marks are owned by WPEngine, Inc.