Yoast SEO <= 26.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'yoast-schema' Block Attribute
Yoast SEO – Advanced SEO with real-time guidance and built-in AI
Minimum safe version
27.2
Update to 27.2 or later to address 32 fixable vulnerabilities
Yoast SEO <= 27.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'jsonText' Block Attribute
CVE-2024-4984
CVE-2024-4041
CVE-2023-40680
Yoast SEO - Security issue which allowed any user to reset settings
Yoast SEO < 1.4.7 - Reset Settings Feature Access Restriction Bypass
Yoast SEO <= 3.2.4 - Subscriber Settings Sensitive Data Exposure
Yoast SEO <= 3.2.5 - Unspecified Cross-Site Scripting (XSS)
WordPress Yoast SEO Plugin <= 20.2 is vulnerable to Cross Site Scripting (XSS)
Yoast SEO <= 20.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Yoast SEO <= 1.4.6 - Missing Authorization
Yoast SEO <= 2.0.1 - Reflected Cross-Site Scripting
Yoast SEO <= 3.2.4 - Sensitive Data Exposure
Yoast SEO <= 3.2.5 - Cross-Site Scripting
WordPress SEO by Yoast Plugin <= 2.0.1 - Cross Site Scripting
WordPress SEO by Yoast Plugin <= 3.2.4 - Sensitive Data Exposure
WordPress SEO by Yoast Plugin <= 3.2.5 - Cross Site Scripting
WordPress SEO by Yoast Plugin <= 1.4.6 - Bypass
WordPress SEO by Yoast Plugin <= 1.4.4 - Unknown Vulnerability
WordPress SEO by Yoast Plugin <= 3.4.0 - Cross Site Scripting
WordPress Yoast SEO plugin <= 3.3.1 - Cross-site Request Forgery (CSRF) Vulnerability
WordPress Yoast SEO plugin <=5.7.1 - Unauthenticated Cross-Site Scripting (XSS) vulnerability
WordPress Yoast SEO plugin <= 9.1.0 - Authenticated Command Execution vulnerability
CVE-2015-2293
CVE-2015-2292
CVE-2012-6692
Yoast SEO <= 5.7.1 - Reflected Cross-Site Scripting
CVE-2018-19370
WordPress Yoast SEO plugin 1.2.0-11.5 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability
CVE-2021-24153
CVE-2021-25118