WordPress security by component
Yoast SEO – Advanced SEO with real-time guidance and built-in AI
Plugin description
Yoast SEO – Advanced SEO with real-time guidance and built-in AI is a WordPress component with 11 published CVE records in this archive. The latest tracked vulnerability was published Jul 25, 2026; the highest CVE/CNA score is 6.8.
Plugin slug:
wordpress-seoLatest vulnerability
CVE-2026-15425: Yoast SEO post slugs permit stored XSS in the bulk editor
Yoast SEO through 28.0 lets an Author store a malicious percent-encoded post_name value when pretty permalinks are enabled. The legacy SEO bulk editor calls get_permalink() for the post, removes the site prefix, decodes the resulting display slug with rawurldecode() and places it into the Page URL/Slug link without HTML escaping. Decoding therefore turns the stored slug back into attacker-controlled markup that can execute in the browser of a user who views the affected bulk-editor row.
| Safe version |
|
||
|---|---|---|---|
| Jul 25, 2026 |
CVE-2026-15425
Yoast SEO post slugs permit stored XSS in the bulk editor
Yoast SEO through 28.0 lets an Author store a malicious percent-encoded post_name value when pretty permalinks are enabled. The legacy SEO bulk editor calls get_permalink() for the post, removes the site prefix, decodes the resulting display slug with rawurldecode() and places it into the Page URL/Slug link without HTML escaping. Decoding therefore turns the stored slug back into attacker-controlled markup that can execute in the browser of a user who views the affected bulk-editor row.
|
28.1 |
CVE6.4
NVDPending
|
| May 27, 2026 |
CVE-2025-14481
Yoast SEO – Advanced SEO with real-time guidance and built-in AI: A security weakness
Yoast SEO – Advanced SEO with real-time guidance and built-in AI is affected by a security weakness. Exploitation requires at least contributor-level access. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 26.5.
|
> 26.5 |
CVE4.3
NVDPending
|
| Mar 22, 2026 |
CVE-2026-3427
Yoast SEO – Advanced SEO with real-time guidance and built-in AI: Cross-site scripting
Yoast SEO – Advanced SEO with real-time guidance and built-in AI is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Feb 06, 2026 |
CVE-2026-1293
Yoast SEO – Advanced SEO with real-time guidance and built-in AI: Cross-site scripting
Yoast SEO – Advanced SEO with real-time guidance and built-in AI is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| May 14, 2024 |
CVE-2024-4041
Yoast SEO: Cross-site scripting
Yoast SEO is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVDPending
|
| Nov 30, 2023 |
CVE-2023-40680
Yoast SEO: Cross-site scripting
Yoast SEO is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.9
NVD4.8
|
| Nov 28, 2018 |
CVE-2018-19370
Wordpress Seo: A security weakness
Wordpress Seo is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.6
NVD6.6
|
| Nov 16, 2017 |
CVE-2017-16842
Wordpress Seo: Cross-site scripting
Wordpress Seo is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.8
NVD4.8
|
| Jun 17, 2015 |
CVE-2012-6692
Wordpress Seo: Cross-site scripting
Wordpress Seo is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Mar 17, 2015 |
CVE-2015-2293
Wordpress Seo: SQL injection
Wordpress Seo is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE6.8
NVD6.8
|
| Mar 17, 2015 |
CVE-2015-2292
Wordpress Seo: SQL injection
Wordpress Seo is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE6.5
NVD6.5
|