Yoast SEO Premium 25.7-25.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

2025-10-02 00:00
stealthcopter

Strategic Overview

Status
Patched in 26.0
Affected PluginYoast SEO Premium
Affected Version25.7 – 25.9
CVSS6.4Medium
CVECVE-2025-11241
View all Yoast SEO Premium vulnerabilities

Vulnerability Overview

The Yoast SEO Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions 25.7 to 25.9 due to a flawed regex used to remove an attribute in post content, which can be abused to inject arbitrary HTML attributes, including JavaScript event handlers. This vulnerability allows a user with Contributor access or higher to create a post containing a malicious JavaScript payload.

Technical Analysis

REMEDIATION: Update to version 26.0, or a newer patched version --- IDENTIFIER: CWE-80 (Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)) The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as <, >, and & that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C