Release date:
Updated on: 2013-09-23
Affected Systems:
WordPress Lazy SEO 1.1.9
Description:
--------------------------------------------------------------------------------
The Wordpress Lazy SEO plug-in can automatically optimize the website and optimize the search engine with specific keywords and location sets.
The Lazy SEO plug-in lazyseo. php has a security vulnerability that allows remote attackers to upload shell code.
<* Source: Ashiyane Digital Security Team
Link: http://www.exploit-db.com/exploits/28452/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
WordPress
---------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://wordpress.org/plugins/lazy-seo