Stored Cross-Site Scripting in Yoast SEO Plugin for WordPress
CVE-2026-15425
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 25 July 2026
What is CVE-2026-15425?
The Yoast SEO plugin for WordPress, known for its advanced SEO features and AI capabilities, is susceptible to a Stored Cross-Site Scripting vulnerability. This flaw exists due to inadequate input sanitization and output escaping on the post slug (post_name), affecting all versions up to and including 28.0. Authenticated users with author-level access or higher can exploit this vulnerability to insert arbitrary web scripts into web pages. These scripts will execute whenever a user visits a page that has been injected with malicious content, particularly with pretty permalinks enabled, increasing the potential for successful exploitation. Proper security measures should be taken to mitigate this risk.
Affected Version(s)
Yoast SEO β Advanced SEO with real-time guidance and built-in AI 0 <= 28.0