{"error":0,"message":null,"data":{"name":"Yoast SEO Premium","plugin":"wordpress-seo-premium","link":"https:\/\/yoast.com\/wordpress\/plugins\/seo\/","latest":null,"closed":null,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"72b0914d89e46ee0e529c3919ef77680d726f7deb39e5297502ab32513b8d7ab","name":"Yoast SEO Premium [wordpress-seo-premium] < 11.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"11.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2019-13478","name":"CVE-2019-13478","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2019-13478","description":"[en] The Yoast SEO plugin before 11.6-RC5 for WordPress does not properly restrict unfiltered HTML in term descriptions.","date":"2019-07-09"},{"id":"d291f62007ebfaaa030e01a68cfd2f5e7c03f140","name":"Yoast SEO <= 11.5 - Authenticated Stored Cross Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wordpress-seo\/yoast-seo-115-authenticated-stored-cross-site-scripting","description":"The Yoast SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via term descriptions in versions up to, and including, 11.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with post editor access to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2019-07-09"},{"id":"8bc4cf95-79f7-4d92-b320-a841ab7e6a6f","name":"Yoast SEO 1.2.0-11.5 - Authenticated Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/8bc4cf95-79f7-4d92-b320-a841ab7e6a6f","description":"The vendor&#039;s description, reference included below:\r\n\r\n&quot;Yoast SEO 11.6 also fixes a security issue regarding term pages in WordPress. Unfiltered code was allowed in some fields. This, however, does not pose a problem for single user sites. In specific cases, on multisite installs, this might become an issue because of the way user roles function.&quot;","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"9.8","severity":"c","exploitable":"3.9","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"9.8","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"3.9","impact":"5.9"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"3044aa9d3486a42320debb2dbd59991591ff914c040ce5723de9dd0e3e39c2d8","name":"Yoast SEO Premium [wordpress-seo-premium] < 20.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"20.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-28775","name":"CVE-2023-28775","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-28775","description":"[en] Missing Authorization vulnerability in Yoast Yoast SEO Premium.This issue affects Yoast SEO Premium: from n\/a through 20.4.","date":"2024-06-11"},{"id":"6beee0870ab39ade540ea260351bb450093c2172","name":"WordPress  Yoast SEO Premium Plugin  <= 20.4 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wordpress-seo-premium\/vulnerability\/wordpress-yoast-seo-premium-plugin-20-4-unauthenticated-zapier-api-key-reset-vulnerability","description":"No patched version available.\nRafie Muhammad (Patchstack) discovered and reported this Broken Access Control vulnerability in WordPress Yoast SEO Premium Plugin.  This vulnerability has been fixed in version 20.5.","date":"2023-05-09"},{"id":"5630f1867c51dfa4b50e2db3dea3bd608d647600","name":"Yoast SEO Premium <= 20.4 - Missing Authorization to Zapier Key Reset","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wordpress-seo-premium\/yoast-seo-premium-204-missing-authorization-to-zapier-key-reset","description":"The Yoast SEO Premium plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in versions up to, and including, 20.4. This makes it possible for unauthenticated attackers to disconnect a Zapier API Key.","date":"2023-05-09"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:N\/A:L","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"n","a":"l","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:N\/A:L","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"none","a":"low","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"b5775c760ffe77b29e27e40582d012301917cb89b0b6a2a49c0e8d5cee6e131f","name":"Yoast SEO Premium [wordpress-seo-premium] < 2.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"42d994ec-9da9-4dd6-9d44-347becaedb3a","name":"WordPress SEO by Yoast &lt;= 2.0.1 - Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/42d994ec-9da9-4dd6-9d44-347becaedb3a","description":"The wordpress-seo-premium WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.","date":null}],"impact":[]},{"uuid":"d8be6bc7225259cff54387f87a92f524d7be351597c313e21574c4dd610554c0","name":"Yoast SEO Premium [wordpress-seo-premium] >= 25.7 - < 26.0","description":null,"operator":{"min_version":"25.7","min_operator":"ge","max_version":"26.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-11241","name":"CVE-2025-11241","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-11241","description":"[en] The Yoast SEO Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions 25.7 to 25.9 due to a flawed regex used to remove an attribute in post content, which can be abused to inject arbitrary HTML attributes, including JavaScript event handlers. This vulnerability allows a user with Contributor access or higher to create a post containing a malicious JavaScript payload.","date":"2025-10-03"},{"id":"EUVD-2025-32218","name":"EUVD-2025-32218","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-32218","description":"The Yoast SEO Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions 25.7 to 25.9 due to a flawed regex used to remove an attribute in post content, which can be abused to inject arbitrary HTML attributes, including JavaScript event handlers. This vulnerability allows a user with Contributor access or higher to create a post containing a malicious JavaScript payload.","date":"2025-10-03"},{"id":"5fd7ec92043f5597d7918a5174613a51f050f6d3","name":"WordPress Yoast SEO Premium Plugin 25.7-25.9 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wordpress-seo-premium\/vulnerability\/wordpress-yoast-seo-premium-plugin-25-7-25-9-authenticated-contributor-stored-cross-site-scripting-vulnerability","description":"<p>WordPress Yoast SEO Premium Plugin 25.7-25.9 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Yoast SEO Premium<\/p><p>Fixed in version 26.0 <\/p><p>Affected Version 25.7-25.9<\/p><p>CVE: CVE-2025-11241<\/p>","date":"2025-10-03"},{"id":"89566d9ae1da0c18964f9798dbc13bdb7a04f885","name":"Yoast SEO Premium 25.7-25.9 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wordpress-seo-premium\/yoast-seo-premium-257-259-authenticated-contributor-stored-cross-site-scripting","description":"The Yoast SEO Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions 25.7 to 25.9 due to a flawed regex used to remove an attribute in post content, which can be abused to inject arbitrary HTML attributes, including JavaScript event handlers. This vulnerability allows a user with Contributor access or higher to create a post containing a malicious JavaScript payload.","date":"2025-10-02"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"3.1","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"3.1","impact":"2.7"},"cwe":[{"cwe":"CWE-80","name":"Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)","description":"The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as \"<\", \">\", and \"&\" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"144a1a21977294630d674233593d894b453d6c3b3115a7a0ed76ef9398f9802f","name":"Yoast SEO Premium [wordpress-seo-premium] < 26.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"26.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-40722","name":"CVE-2026-40722","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-40722","description":"[en] Missing Authorization vulnerability in Yoast BV Yoast SEO Premium allows Exploiting Incorrectly Configured Access Control Security Levels.\n\nThis issue affects Yoast SEO Premium: from n\/a through 26.6.","date":"2026-06-17"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:C\/C:N\/I:L\/A:L","av":"n","ac":"l","pr":"h","ui":"n","s":"c","c":"n","i":"l","a":"l","score":"5.5","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:C\/C:N\/I:L\/A:L","score":"5.5","severity":"medium","av":"network","ac":"low","pr":"high","ui":"none","s":"changed","c":"none","i":"low","a":"low","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"959c9f212cc59a7f8388832d00e244ca64691d074ca7b2be5889e49d9cde8412","name":"Yoast SEO Premium [wordpress-seo-premium] < 27.6.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"27.6.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-10821","name":"CVE-2026-10821","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-10821","description":"[en] The Yoast SEO Premium WordPress plugin before 27.6.1 does not sanitize control characters from redirect origins before writing them to the site's Apache configuration file when the file-based redirect mode is enabled, and the redirect-creation endpoint is reachable by users with only Author-level access. This allows such users to inject arbitrary newline-delimited Apache directives into the root .htaccess file. On Apache servers that honour PHP directives, the injection can be chained with the user's own media upload (a polyglot image carrying a PHP payload) and an auto_prepend_file directive to achieve Remote Code Execution.","date":"2026-09-02"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"h","pr":"h","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"6.6","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"6.6","severity":"medium","av":"network","ac":"high","pr":"high","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-74","name":"Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')","description":"The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}}]},"updated":"1788501918"}