Security patch: Yoast SEO Premium 27.6.1

Yoast SEO Premium 27.6.1 is out now. This release contains a security fix affecting the Redirect Manager in Yoast SEO Premium. The good news: the vast majority of users are not impacted. If you’re a customer of Yoast SEO Premium, Yoast WooCommerce SEO, or Yoast SEO AI+, please read on. 

Are you affected? 

The vast majority of customers are not impacted. Your site is only potentially at risk if all three of the following are true: 

What was the issue? 

An authenticated user could inject unexpected configuration into a site’s .htaccess file by including special characters in a redirect. Depending on what was injected, this could range from a site crash to, in the most serious cases, remote code execution.  

We have reviewed a sample of sites using the affected configuration and found no evidence of exploitation. There are no known cases of abuse. 

What’s fixed 

The patch includes three layers of protection: 

What you should do 

Please update to 27.6.1 from the WordPress plugins screen, your Admin can do this in under two minutes. 

If you meet all three conditions above, we recommend updating as soon as possible. Should you not, the security fix doesn’t apply to your setup, but keeping your plugins current is always good practice, and 27.6.1 is the version we recommend for everyone. 

If you’re unsure whether you’re affected, check your redirect settings directly at [www.yoursite.com]/wp-admin/admin.php?page=wpseo_redirects#/redirect-method if you don’t see .htaccess mode enabled, you’re not at risk. 

Security method in app UI

A full security advisory will be published soon. If you have any questions or concerns in the meantime, our support team is here to help you. 

Thank you for your continued trust in Yoast. 

The post Security patch: Yoast SEO Premium 27.6.1 appeared first on Yoast.