Extension WordPress
Vulnérabilités Yoast SEO – Advanced SEO with real-time guidance and built-in AI
Cette page rassemble les failles publiées pour Yoast SEO – Advanced SEO with real-time guidance and built-in AI, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Yoast SEO – Advanced SEO with real-time guidance and built-in AI
19 fiches
Yoast SEO <= 26.5 – Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Exposure via 'post_id' Parameter
The Yoast SEO plugin for WordPress is vulnerable to Insecure Direct Object References in all versions up to, and including, 26.5. This is due to insufficient authorization checks in the Meta Search REST API endpoint that fail to…
*-26.5
26.6
26/05/2026
Yoast SEO <= 27.1.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'jsonText' Block Attribute
The Yoast SEO – Advanced SEO with real-time guidance and built-in AI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the `jsonText` block attribute in all versions up to, and including, 27.1.1 due to insufficient…
*-27.1.1
27.2
21/03/2026
Yoast SEO <= 26.8 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'yoast-schema' Block Attribute
The Yoast SEO – Advanced SEO with real-time guidance and built-in AI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the `yoast-schema` block attribute in all versions up to, and including, 26.8 due to insufficient…
*-26.8
26.9
05/02/2026
Yoast SEO <= 22.6 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Yoast SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘display_name’ author meta in all versions up to, and including, 22.6 due to insufficient input sanitization and output escaping. This makes it possible for…
*-22.6
22.7
14/05/2024
Yoast SEO <= 22.5 – Reflected Cross-Site Scripting
The Yoast SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URLs in all versions up to, and including, 22.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
*-22.5
22.6
06/05/2024
Yoast SEO <= 21.0 – Authenticated (Seo Manager+) Stored Cross-Site Scripting
The Yoast SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 21.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with seo manager-level access…
*-21.0
21.1
24/11/2023
Yoast SEO <= 20.2 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Yoast SEO plugin for WordPress is vulnerable to DOM-based Cross-Site Scripting via individual post SEO details in versions up to, and including, 20.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
*-20.2
20.2.1
02/03/2023
Yoast SEO <= 17.2 – Full Path Disclosure
The Yoast SEO plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 17.2 via the /wp/v2/posts REST endpoints that discloses the full internal path of featured images from posts. This makes it…
[*, 17.3)
17.3
05/10/2021
Yoast SEO <= 11.5 – Authenticated Stored Cross Site Scripting
The Yoast SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via term descriptions in versions up to, and including, 11.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with…
*-11.5
11.6-RC5
09/07/2019
Yoast SEO <= 9.1.0 – Race Condition to Remote Code Execution
A Race condition vulnerability in unzip_file in admin/import/class-import-settings.php in the Yoast SEO (wordpress-seo) plugin before 9.2.0 for WordPress allows an SEO Manager to perform command execution on the Operating System via a ZIP import.
*-9.1.0
9.2.0
06/11/2018
Yoast SEO <= 5.7.1 – Reflected Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in admin/google_search_console/class-gsc-table.php in the Yoast SEO plugin before 5.8.0 for WordPress allows remote attackers to inject arbitrary web script or HTML.
*-5.7.1
5.8.0
22/11/2017
Yoast SEO <= 3.4.0 – Authenticated Stored Cross-Site Scripting
A Stored Cross-Site Scripting vulnerability was discovered in the Yoast SEO WordPress plugin before 3.4.1, which had built-in blacklist filters which were blacklisting parentheses as well as several functions such as alert, but bypasses were found.
[*, 3.4.1)
3.4.1
02/08/2016
Yoast SEO <= 3.2.5 – Cross-Site Scripting
The Yoast SEO plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 3.2.5 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that…
*-3.2.5
3.3.0
14/06/2016
Yoast SEO <= 3.2.4 – Sensitive Data Exposure
The Yoast SEO plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including 3.2.4. This is due to privileged AJAX actions being executable by regular users. This makes it possible for registered attackers…
*-3.2.4
3.2.5
06/05/2016
Yoast SEO <= 2.0.1 – Reflected Cross-Site Scripting
The Yoast SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.0.1 due to insufficient input sanitization and output escaping on remove_query_arg and add_query_arg. This makes it possible for attackers to…
[*, 2.1)
2.1
20/04/2015
Yoast SEO <= 1.7.3.3 – Blind SQL Injection
Multiple SQL injection vulnerabilities in admin/class-bulk-editor-list-table.php in the WordPress SEO by Yoast plugin before 1.5.7, 1.6.x before 1.6.4, and 1.7.x before 1.7.4 for WordPress allow remote authenticated users to execute arbitrary SQL commands via the (1) order_by or…
*-1.5.6, 1.6-1.6.3, 1.7-1.7.3
1.5.7, 1.6.4, 1.7.4
11/03/2015
Yoast SEO <= 1.7.3.3 – Cross-Site Request Forgery
Multiple cross-site request forgery (CSRF) vulnerabilities in admin/class-bulk-editor-list-table.php in the WordPress SEO by Yoast plugin before 1.5.7, 1.6.x before 1.6.4, and 1.7.x before 1.7.4 for WordPress allow remote attackers to hijack the authentication of certain users for requests…
*-1.5.6, 1.6-1.6.3, 1.7-1.7.3.3
1.5.7, 1.6.4, 1.7.4
10/03/2015
Yoast SEO <= 1.4.6 – Missing Authorization
The Yoast SEO plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the reset settings function in versions up to, and including, 1.4.6. This makes it possible for unauthorized attackers to reset…
*-1.4.6
1.4.7
01/08/2014
Yoast SEO <= 2.1.1 – Cross Site Scripting via post_title parameter
Cross-site scripting (XSS) vulnerability in js/wp-seo-metabox.js in the WordPress SEO by Yoast plugin before 2.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the post_title parameter to wp-admin/post-new.php, which is not properly handled…
*-2.1.1
2.2
31/10/2012
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.