Yoast SEO <= 28.0 - Authenticated (Author+) Stored Cross-Site Scripting via Post Slug (post_name)
medium
The Yoast SEO – Advanced SEO with real-time guidance and built-in AI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Slug (post_name) in all versions up to, and including, 28.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with...
- CVSS:
- 6.4
- Affected:
- up to 28.0
- Fixed in:
- 28.1
- Disclosed:
- Jul 24, 2026
CVE-2026-15425 on NVD →
Yoast SEO <= 26.5 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Exposure via 'post_id' Parameter
medium
The Yoast SEO plugin for WordPress is vulnerable to Insecure Direct Object References in all versions up to, and including, 26.5. This is due to insufficient authorization checks in the Meta Search REST API endpoint that fail to verify post ownership. This makes it possible for authenticated attackers, with Contributor...
- CVSS:
- 4.3
- Affected:
- up to 26.5
- Fixed in:
- 26.6
- Disclosed:
- May 26, 2026
CVE-2025-14481 on NVD →
Yoast SEO - Authenticated (Contributor+) Stored Cross-Site Scripting via 'jsonText' Block Attribute vulnerability
medium
Authenticated (Contributor+) Stored Cross-Site Scripting via 'jsonText' Block Attribute vulnerability
- CVSS:
- 6.5
- Affected:
- up to 27.1.1
- Fixed in:
- 27.2
- Disclosed:
- Mar 23, 2026
Yoast SEO <= 27.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'jsonText' Block Attribute
medium
The Yoast SEO – Advanced SEO with real-time guidance and built-in AI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the `jsonText` block attribute in all versions up to, and including, 27.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated...
- CVSS:
- 6.4
- Affected:
- up to 27.1.1
- Fixed in:
- 27.2
- Disclosed:
- Mar 21, 2026
CVE-2026-3427 on NVD →
Yoast SEO <= 26.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'yoast-schema' Block Attribute
medium
The Yoast SEO – Advanced SEO with real-time guidance and built-in AI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the `yoast-schema` block attribute in all versions up to, and including, 26.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticate...
- CVSS:
- 6.4
- Affected:
- up to 26.8
- Fixed in:
- 26.9
- Disclosed:
- Feb 5, 2026
CVE-2026-1293 on NVD →
Yoast SEO – Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 22.7
unknown
[en] The Yoast SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘display_name’ author meta in all versions up to, and including, 22.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to i...
- Affected:
- up to 22.7
- Fixed in:
- 22.7
- Disclosed:
- May 16, 2024
CVE-2024-4984 on NVD →
Yoast SEO <= 22.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Yoast SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘display_name’ author meta in all versions up to, and including, 22.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject...
- CVSS:
- 6.4
- Affected:
- up to 22.6
- Fixed in:
- 22.7
- Disclosed:
- May 14, 2024
CVE-2024-4984 on NVD →
Yoast SEO – Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 22.6
unknown
[en] The Yoast SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URLs in all versions up to, and including, 22.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can s...
- Affected:
- up to 22.6
- Fixed in:
- 22.6
- Disclosed:
- May 9, 2024
CVE-2024-4041 on NVD →
Yoast SEO <= 22.5 - Reflected Cross-Site Scripting
medium
The Yoast SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URLs in all versions up to, and including, 22.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succes...
- CVSS:
- 6.1
- Affected:
- up to 22.5
- Fixed in:
- 22.6
- Disclosed:
- May 6, 2024
CVE-2024-4041 on NVD →
Yoast SEO – Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 21.1
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Team Yoast Yoast SEO allows Stored XSS.This issue affects Yoast SEO: from n/a through 21.0.
- Affected:
- up to 21.1
- Fixed in:
- 21.1
- Disclosed:
- Nov 30, 2023
CVE-2023-40680 on NVD →
Yoast SEO <= 21.0 - Authenticated (Seo Manager+) Stored Cross-Site Scripting
medium
The Yoast SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 21.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with seo manager-level access and above, to inject arbitrary web scripts in pages that wi...
- CVSS:
- 5.5
- Affected:
- up to 21.0
- Fixed in:
- 21.1
- Disclosed:
- Nov 24, 2023
CVE-2023-40680 on NVD →
Yoast SEO – Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 20.2.1
unknown
Update the WordPress Yoast SEO plugin to the latest available version (at least 20.2.1).
WordFence discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Yoast SEO Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloa...
- Affected:
- up to 20.2.1
- Fixed in:
- 20.2.1
- Disclosed:
- Mar 3, 2023
Yoast SEO <= 20.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Yoast SEO plugin for WordPress is vulnerable to DOM-based Cross-Site Scripting via individual post SEO details in versions up to, and including, 20.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-level requirements and above, to injec...
- CVSS:
- 6.4
- Affected:
- up to 20.2
- Fixed in:
- 20.2.1
- Disclosed:
- Mar 2, 2023
Yoast SEO – Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 20.2.1
unknown
The Yoast SEO plugin for WordPress is vulnerable to DOM-based Cross-Site Scripting via individual post SEO details in versions up to, and including, 20.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-level requirements and above, to injec...
- Affected:
- up to 20.2.1
- Fixed in:
- 20.2.1
- Disclosed:
- Mar 2, 2023
Yoast SEO – Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 17.3
unknown
[en] The Yoast SEO WordPress plugin (from versions 16.7 until 17.2) discloses the full internal path of featured images in posts via the wp/v2/posts REST endpoints which could help an attacker identify other vulnerabilities or help during the exploitation of other identified vulnerabilities.
- Affected:
- up to 17.3
- Fixed in:
- 17.3
- Disclosed:
- Feb 28, 2022
CVE-2021-25118 on NVD →
Yoast SEO <= 17.2 - Full Path Disclosure
medium
The Yoast SEO plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 17.2 via the /wp/v2/posts REST endpoints that discloses the full internal path of featured images from posts. This makes it possible for unauthenticated attackers to extract sensitive data which consists of ful...
- CVSS:
- 5.3
- Affected:
- up to 17.3
- Fixed in:
- 17.3
- Disclosed:
- Oct 5, 2021
CVE-2021-25118 on NVD →
Yoast SEO – Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 3.4.1
unknown
[en] A Stored Cross-Site Scripting vulnerability was discovered in the Yoast SEO WordPress plugin before 3.4.1, which had built-in blacklist filters which were blacklisting Parenthesis as well as several functions such as alert but bypasses were found.
- Affected:
- up to 3.4.1
- Fixed in:
- 3.4.1
- Disclosed:
- Apr 5, 2021
CVE-2021-24153 on NVD →
Yoast SEO <= 11.5 - Authenticated Stored Cross Site Scripting
medium
The Yoast SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via term descriptions in versions up to, and including, 11.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with post editor access to inject arbitrary web scripts in pages tha...
- CVSS:
- 6.4
- Affected:
- up to 11.5
- Fixed in:
- 11.6-RC5
- Disclosed:
- Jul 9, 2019
CVE-2019-13478 on NVD →
Yoast SEO – Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 11.6
unknown
[en] The Yoast SEO plugin before 11.6-RC5 for WordPress does not properly restrict unfiltered HTML in term descriptions.
- Affected:
- up to 11.6
- Fixed in:
- 11.6
- Disclosed:
- Jul 9, 2019
CVE-2019-13478 on NVD →
Yoast SEO – Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 9.2.0
unknown
[en] A Race condition vulnerability in unzip_file in admin/import/class-import-settings.php in the Yoast SEO (wordpress-seo) plugin before 9.2.0 for WordPress allows an SEO Manager to perform command execution on the Operating System via a ZIP import.
- Affected:
- up to 9.2.0
- Fixed in:
- 9.2.0
- Disclosed:
- Nov 28, 2018
CVE-2018-19370 on NVD →
Yoast SEO – Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 9.2.0
unknown
Authenticated Command Execution vulnerability found by Dimopoulos Elias in WordPress Yoast SEO plugin (versions <= 9.1).
- Affected:
- up to 9.2.0
- Fixed in:
- 9.2.0
- Disclosed:
- Nov 20, 2018
Yoast SEO <= 9.1.0 - Race Condition to Remote Code Execution
medium
A Race condition vulnerability in unzip_file in admin/import/class-import-settings.php in the Yoast SEO (wordpress-seo) plugin before 9.2.0 for WordPress allows an SEO Manager to perform command execution on the Operating System via a ZIP import.
- CVSS:
- 6.6
- Affected:
- up to 9.1.0
- Fixed in:
- 9.2.0
- Disclosed:
- Nov 6, 2018
CVE-2018-19370 on NVD →
Yoast SEO <= 5.7.1 - Reflected Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in admin/google_search_console/class-gsc-table.php in the Yoast SEO plugin before 5.8.0 for WordPress allows remote attackers to inject arbitrary web script or HTML.
- CVSS:
- 6.1
- Affected:
- up to 5.7.1
- Fixed in:
- 5.8.0
- Disclosed:
- Nov 22, 2017
CVE-2017-16842 on NVD →
Yoast SEO – Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 5.8.0
unknown
Unauthenticated Cross-Site Scripting (XSS) vulnerability found in WordPress Yoast SEO plugin (versions <=5.7.1). Vulnerability found in "admin/google_search_console/class-gsc-table.php" of the WordPress Yoast SEO plugin versions before version 5.8.0, and it allows remote attackers to inject arbitrary web script or HTML...
- Affected:
- up to 5.8.0
- Fixed in:
- 5.8.0
- Disclosed:
- Nov 20, 2017
Yoast SEO – Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 5.8.0
unknown
[en] Cross-site scripting (XSS) vulnerability in admin/google_search_console/class-gsc-table.php in the Yoast SEO plugin before 5.8.0 for WordPress allows remote attackers to inject arbitrary web script or HTML.
- Affected:
- up to 5.8.0
- Fixed in:
- 5.8.0
- Disclosed:
- Nov 16, 2017
CVE-2017-16842 on NVD →
Yoast SEO – Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 3.3.2
unknown
WordPress Yoast SEO plugin Cross-site Request Forgery (CSRF) exists on /wp-admin/admin.php?page=wpseo_tools&tool=import-export page.
Update the plugin.
- Affected:
- up to 3.3.2
- Fixed in:
- 3.3.2
- Disclosed:
- May 11, 2017
Yoast SEO – Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 3.4.1
unknown
This plugin is prone to a stored cross site scripting vulnerability.
Update the plugin.
- Affected:
- up to 3.4.1
- Fixed in:
- 3.4.1
- Disclosed:
- Aug 3, 2016
Yoast SEO <= 3.4.0 - Authenticated Stored Cross-Site Scripting
medium
A Stored Cross-Site Scripting vulnerability was discovered in the Yoast SEO WordPress plugin before 3.4.1, which had built-in blacklist filters which were blacklisting parentheses as well as several functions such as alert, but bypasses were found.
- CVSS:
- 5.4
- Affected:
- up to 3.4.1
- Fixed in:
- 3.4.1
- Disclosed:
- Aug 2, 2016
CVE-2021-24153 on NVD →
Yoast SEO – Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 1.4.5
unknown
This plugin is prone to an security issue which allowed any user to reset settings.
Update the plugin.
- Affected:
- up to 1.4.5
- Fixed in:
- 1.4.5
- Disclosed:
- Jul 28, 2016
Yoast SEO – Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 1.4.7
unknown
This plugin is prone to a reset settings feature access restriction bypass vulnerability.
Update the plugin.
- Affected:
- up to 1.4.7
- Fixed in:
- 1.4.7
- Disclosed:
- Jul 28, 2016
Yoast SEO <= 3.2.5 - Cross-Site Scripting
medium
The Yoast SEO plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 3.2.5 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 4.7
- Affected:
- up to 3.2.5
- Fixed in:
- 3.3.0
- Disclosed:
- Jun 14, 2016
Yoast SEO – Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 3.3.0
unknown
This plugin is prone to an unspecified cross site scripting vulnerability.
Update the plugin.
- Affected:
- up to 3.3.0
- Fixed in:
- 3.3.0
- Disclosed:
- Jun 14, 2016
Yoast SEO – Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 3.3.0
unknown
The Yoast SEO plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 3.2.5 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- Affected:
- up to 3.3.0
- Fixed in:
- 3.3.0
- Disclosed:
- Jun 14, 2016
Yoast SEO <= 3.2.4 - Sensitive Data Exposure
medium
The Yoast SEO plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including 3.2.4. This is due to privileged AJAX actions being executable by regular users. This makes it possible for registered attackers to extract sensitive data including Yoast SEO settings and post metadata relative...
- CVSS:
- 5.3
- Affected:
- up to 3.2.4
- Fixed in:
- 3.2.5
- Disclosed:
- May 6, 2016
Yoast SEO – Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 3.2.5
unknown
This plugin is prone to a subscriber settings sensitive data exposure vulnerability.
Update the plugin.
- Affected:
- up to 3.2.5
- Fixed in:
- 3.2.5
- Disclosed:
- May 6, 2016
Yoast SEO – Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 3.2.5
unknown
The Yoast SEO plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including 3.2.4. This is due to privileged AJAX actions being executable by regular users. This makes it possible for registered attackers to extract sensitive data including Yoast SEO settings and post metadata relative...
- Affected:
- up to 3.2.5
- Fixed in:
- 3.2.5
- Disclosed:
- May 6, 2016
Yoast SEO – Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 2.2
unknown
[en] Cross-site scripting (XSS) vulnerability in js/wp-seo-metabox.js in the WordPress SEO by Yoast plugin before 2.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the post_title parameter to wp-admin/post-new.php, which is not properly handled in the snippet preview functionality.
- Affected:
- up to 2.2
- Fixed in:
- 2.2
- Disclosed:
- Jun 17, 2015
CVE-2012-6692 on NVD →
Yoast SEO <= 2.0.1 - Reflected Cross-Site Scripting
medium
The Yoast SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.0.1 due to insufficient input sanitization and output escaping on remove_query_arg and add_query_arg. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's bro...
- CVSS:
- 6.1
- Affected:
- up to 2.1
- Fixed in:
- 2.1
- Disclosed:
- Apr 20, 2015
Yoast SEO – Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 2.1
unknown
The Yoast SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.0.1 due to insufficient input sanitization and output escaping on remove_query_arg and add_query_arg. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's bro...
- Affected:
- up to 2.1
- Fixed in:
- 2.1
- Disclosed:
- Apr 20, 2015
Yoast SEO – Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 2.1
unknown
This plugin is prone to cross site scripting vulnerability because of misuse of the add_query_arg() and remove_query_arg() functions.
Update the plugin.
- Affected:
- up to 2.1
- Fixed in:
- 2.1
- Disclosed:
- Apr 20, 2015
Yoast SEO – Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 1.7.4
unknown
[en] Multiple cross-site request forgery (CSRF) vulnerabilities in admin/class-bulk-editor-list-table.php in the WordPress SEO by Yoast plugin before 1.5.7, 1.6.x before 1.6.4, and 1.7.x before 1.7.4 for WordPress allow remote attackers to hijack the authentication of certain users for requests that conduct SQL injecti...
- Affected:
- up to 1.7.4
- Fixed in:
- 1.7.4
- Disclosed:
- Mar 17, 2015
CVE-2015-2293 on NVD →
Yoast SEO – Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 1.7.4
unknown
[en] Multiple SQL injection vulnerabilities in admin/class-bulk-editor-list-table.php in the WordPress SEO by Yoast plugin before 1.5.7, 1.6.x before 1.6.4, and 1.7.x before 1.7.4 for WordPress allow remote authenticated users to execute arbitrary SQL commands via the (1) order_by or (2) order parameter in the wpseo_bu...
- Affected:
- up to 1.7.4
- Fixed in:
- 1.7.4
- Disclosed:
- Mar 17, 2015
CVE-2015-2292 on NVD →
Yoast SEO <= 1.7.3.3 - Blind SQL Injection
high
Multiple SQL injection vulnerabilities in admin/class-bulk-editor-list-table.php in the WordPress SEO by Yoast plugin before 1.5.7, 1.6.x before 1.6.4, and 1.7.x before 1.7.4 for WordPress allow remote authenticated users to execute arbitrary SQL commands via the (1) order_by or (2) order parameter in the wpseo_bulk-ed...
- CVSS:
- 8.8
- Affected:
- up to 1.5.6, 1.6 – 1.6.3, 1.7 – 1.7.3
- Fixed in:
- 1.5.7
- Disclosed:
- Mar 11, 2015
CVE-2015-2292 on NVD →
Yoast SEO <= 1.7.3.3 - Cross-Site Request Forgery
high
Multiple cross-site request forgery (CSRF) vulnerabilities in admin/class-bulk-editor-list-table.php in the WordPress SEO by Yoast plugin before 1.5.7, 1.6.x before 1.6.4, and 1.7.x before 1.7.4 for WordPress allow remote attackers to hijack the authentication of certain users for requests that conduct SQL injection at...
- CVSS:
- 7.5
- Affected:
- up to 1.5.6, 1.6 – 1.6.3, 1.7 – 1.7.3.3
- Fixed in:
- 1.5.7
- Disclosed:
- Mar 10, 2015
CVE-2015-2293 on NVD →
Yoast SEO <= 1.4.6 - Missing Authorization
medium
The Yoast SEO plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the reset settings function in versions up to, and including, 1.4.6. This makes it possible for unauthorized attackers to reset the plugin's settings.
- CVSS:
- 6.5
- Affected:
- up to 1.4.6
- Fixed in:
- 1.4.7
- Disclosed:
- Aug 1, 2014
Yoast SEO – Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 1.4.7
unknown
The Yoast SEO plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the reset settings function in versions up to, and including, 1.4.6. This makes it possible for unauthorized attackers to reset the plugin's settings.
- Affected:
- up to 1.4.7
- Fixed in:
- 1.4.7
- Disclosed:
- Aug 1, 2014
Yoast SEO <= 2.1.1 - Cross Site Scripting via post_title parameter
medium
Cross-site scripting (XSS) vulnerability in js/wp-seo-metabox.js in the WordPress SEO by Yoast plugin before 2.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the post_title parameter to wp-admin/post-new.php, which is not properly handled in the snippet preview functionality.
- CVSS:
- 6.1
- Affected:
- up to 2.1.1
- Fixed in:
- 2.2
- Disclosed:
- Oct 31, 2012
CVE-2012-6692 on NVD →
Yoast SEO – Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 3.3.0
unknown
Changelog file for version 3.3.0 states "Fixes an XSS issue, props Hristo Pandjarov."
- Affected:
- up to 3.3.0
- Fixed in:
- 3.3.0
Yoast SEO – Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 3.2.5
unknown
The Yoast SEO WordPress plugin was affected by a Subscriber Settings Sensitive Data Exposure security vulnerability.
- Affected:
- up to 3.2.5
- Fixed in:
- 3.2.5
Yoast SEO – Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 1.4.7
unknown
The Yoast SEO WordPress plugin was affected by a Reset Settings Feature Access Restriction Bypass security vulnerability.
- Affected:
- up to 1.4.7
- Fixed in:
- 1.4.7
Yoast SEO – Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 1.4.5
unknown
The Yoast SEO WordPress plugin was affected by a Security issue which allowed any user to reset settings security vulnerability.
- Affected:
- up to 1.4.5
- Fixed in:
- 1.4.5