• Resolved robertsiciliano

    (@robertsiciliano)


    WP Engine sent this and there are seemingly issues with 28.1. Plus 28.0 seems to be breaking aspects of y site. What to do here? : “At WP Engine we take the security of your sites very seriously, and make every effort to keep our customers aware of any potential security risks. We are reaching out to you today because we identified resources that may be utilizing a vulnerable version of the wordpress-seo plugin. The site robertsicilian on robertsicilian is running version 28.0. WP Engine summary of the vulnerability: Data from an attacker could be interpreted as code by site visitors’ web browsers. The ability to run code in another site visitors’ browser can be abused to steal information, or modify site configuration. This vulnerability’s information has been verified by Patchstack. Please note that questions related to this notification should be directed to Patchstack, the plugin author or the 3rd-party researcher for the most accurate information. Resources providing further information on this vulnerability: https://patchstack.com/database/vulnerability/wordpress-seo/wordpress-yoast-seo-advanced-seo-with-real-time-guidance-and-built-in-ai-plugin-28-0-authenticated-author-stored-cross-site-scripting-vulnerability?_a_id=473 To secure your site, please upgrade to the latest version of this plugin. We always suggest making a backup before making any changes. You can learn how to do this in this article: https://wpengine.com/support/restore/. Would you like to avoid doing these updates manually in the future? Add the Smart Plugin Manager: https://my.wpengine.com/products/smart_plugin_manager to your plan today! Finally, feel free to reach out to our Support team if you need assistance with backing up or updating your website! Thanks, -WP Engine Security Team”

    The page I need help with: [log in to see the link]

Viewing 1 replies (of 1 total)
  • Plugin Support Maybellyne

    (@maybellyne)

    Hello @robertsiciliano,

    Thanks for sharing the vulnerability notification from WPEngine with us. The notification states that your website is running v28.0, while the Patchstack report states that running v28.1 resolves the vulnerability. Do let us know if you still get a notification from WPEngine after updating to Yoast SEO v28.1.

Viewing 1 replies (of 1 total)

You must be logged in to reply to this topic.