← WordPress Vulnerabilities
WordPress security by component

Yoast SEO – Advanced SEO with real-time guidance and built-in AI

Yoast SEO – Advanced SEO with real-time guidance and built-in AI is a WordPress component with 11 published CVE records in this archive. The latest tracked vulnerability was published Jul 25, 2026; the highest CVE/CNA score is 6.8.

Plugin slug: wordpress-seo

CVE-2026-15425: Yoast SEO post slugs permit stored XSS in the bulk editor

Yoast SEO through 28.0 lets an Author store a malicious percent-encoded post_name value when pretty permalinks are enabled. The legacy SEO bulk editor calls get_permalink() for the post, removes the site prefix, decodes the resulting display slug with rawurldecode() and places it into the Page URL/Slug link without HTML escaping. Decoding therefore turns the stored slug back into attacker-controlled markup that can execute in the browser of a user who views the affected bulk-editor row.

PublishedJul 25, 2026
Known safe version28.1
Safe version
Jul 25, 2026 CVE-2026-15425
Yoast SEO post slugs permit stored XSS in the bulk editor
Yoast SEO through 28.0 lets an Author store a malicious percent-encoded post_name value when pretty permalinks are enabled. The legacy SEO bulk editor calls get_permalink() for the post, removes the site prefix, decodes the resulting display slug with rawurldecode() and places it into the Page URL/Slug link without HTML escaping. Decoding therefore turns the stored slug back into attacker-controlled markup that can execute in the browser of a user who views the affected bulk-editor row.
28.1
CVE6.4
NVDPending
May 27, 2026 CVE-2025-14481
Yoast SEO – Advanced SEO with real-time guidance and built-in AI: A security weakness
Yoast SEO – Advanced SEO with real-time guidance and built-in AI is affected by a security weakness. Exploitation requires at least contributor-level access. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 26.5.
> 26.5
CVE4.3
NVDPending
Mar 22, 2026 CVE-2026-3427
Yoast SEO – Advanced SEO with real-time guidance and built-in AI: Cross-site scripting
Yoast SEO – Advanced SEO with real-time guidance and built-in AI is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Feb 06, 2026 CVE-2026-1293
Yoast SEO – Advanced SEO with real-time guidance and built-in AI: Cross-site scripting
Yoast SEO – Advanced SEO with real-time guidance and built-in AI is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
May 14, 2024 CVE-2024-4041
Yoast SEO: Cross-site scripting
Yoast SEO is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVDPending
Nov 30, 2023 CVE-2023-40680
Yoast SEO: Cross-site scripting
Yoast SEO is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVD4.8
Nov 28, 2018 CVE-2018-19370
Wordpress Seo: A security weakness
Wordpress Seo is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.6
NVD6.6
Nov 16, 2017 CVE-2017-16842
Wordpress Seo: Cross-site scripting
Wordpress Seo is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8
Jun 17, 2015 CVE-2012-6692
Wordpress Seo: Cross-site scripting
Wordpress Seo is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.3
NVD4.3
Mar 17, 2015 CVE-2015-2293
Wordpress Seo: SQL injection
Wordpress Seo is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE6.8
NVD6.8
Mar 17, 2015 CVE-2015-2292
Wordpress Seo: SQL injection
Wordpress Seo is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE6.5
NVD6.5