CVE-2023-28775

WordPress Yoast SEO Premium plugin <= 20.4 - Unauthenticated Zapier API Key Reset vulnerability

Missing Authorization vulnerability in Yoast Yoast SEO Premium.This issue affects Yoast SEO Premium: from n/a through 20.4.


We have discovered 116,153 live websites that are affected by CVE-2023-28775.

Run a Free Instant Scan




Affected Software

Product  Yoast SEO Premium
Category Search Engine Optimization
Vulnerable Domains116,153 live websites (41.09% of Yoast SEO Premium install base)
Vulnerable Versions
  • from 0 through 20.4
Vulnerable Versions Count246 versions ( 82.27% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Jun 11, 2024
  • Updated - Aug 2, 2024

Credits

  • Rafie Muhammad (Patchstack) (finder)

CVE-2023-28775 usage by Country

United States51,247 websites



Germany9,545 websites
Iran5,698 websites
Vietnam4,746 websites
Russia4,417 websites
France4,367 websites
GB3,568 websites
Italy2,532 websites
Cyprus2,159 websites
Spain1,981 websites

CVE-2023-28775 usage by TLD

.com58,374 websites
.ru3,729 websites
.org3,710 websites
.de3,035 websites
.net2,942 websites
.com.br2,737 websites
.co.uk2,675 websites
.it2,192 websites
.com.au1,997 websites
.nl1,879 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-28775

Top websites that are affected by CVE-2023-28775. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.com United States***
************.com United States*,***
***********.com United States*,***
******.com United States*,***
******.com United States*,***
*******.com United States*,***
**************.com United States*,***
*************.com United States*,***
*****.com United States*,***
***.org United States*,***
See full domain list

FAQ

CVE-2023-28775 is Missing Authorization in Yoast SEO Premium
A total of 116,153 websites have been identified as vulnerable to CVE-2023-28775, based on global website indexing conducted by WebTechSurvey.
The Yoast SEO Premium is affected by the CVE-2023-28775 vulnerability.
Yoast SEO Premium versions up to and including 20.4 are vulnerable to CVE-2023-28775.