Stored Cross-Site Scripting in Yoast SEO Plugin for WordPress
CVE-2026-15425

6.4MEDIUM

What is CVE-2026-15425?

The Yoast SEO plugin for WordPress, known for its advanced SEO features and AI capabilities, is susceptible to a Stored Cross-Site Scripting vulnerability. This flaw exists due to inadequate input sanitization and output escaping on the post slug (post_name), affecting all versions up to and including 28.0. Authenticated users with author-level access or higher can exploit this vulnerability to insert arbitrary web scripts into web pages. These scripts will execute whenever a user visits a page that has been injected with malicious content, particularly with pretty permalinks enabled, increasing the potential for successful exploitation. Proper security measures should be taken to mitigate this risk.

Affected Version(s)

Yoast SEO – Advanced SEO with real-time guidance and built-in AI 0 <= 28.0

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dmitrii Ignatyev
.