Arbitrary Code Execution Vulnerability in Yoast SEO Premium Plugin for WordPress
CVE-2026-10821
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 2 September 2026
Badges
What is CVE-2026-10821?
The Yoast SEO Premium WordPress plugin prior to version 27.6.1 exhibits a security flaw where it fails to properly sanitize control characters from redirect origins before writing to the site's Apache configuration file. This issue arises when file-based redirection is enabled and the redirect-creation endpoint is accessible to users with Author-level permissions. As a result, these users can inject malicious newline-delimited Apache directives into the site's root .htaccess file. If the Apache server processes PHP directives, the vulnerabilities can be exploited in conjunction with a user's media uploads (e.g., a specially crafted polyglot image containing a PHP payload) combined with an auto_prepend_file directive, potentially leading to Remote Code Execution.
Affected Version(s)
Yoast SEO Premium 0 < 27.6.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved