CVE Database /
CVE-2021-24153
CVE · Medium
CVE-2021-24153 — Yoast SEO – Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 3.4.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2021-24153
|
Yoast SEO – Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 3.4.1 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
5.4
|
< 3.4.1
|
3.4.1 |
2016-08-02 |
—
|
CVE-2021-24153
The Yoast SEO plugin before version 3.4.1 contained a stored cross-site scripting flaw that allowed attackers to inject malicious scripts into the application. Although the plugin implemented a blacklist to block dangerous elements including parentheses and functions like alert, researchers identified methods to circumvent these restrictions. This vulnerability could enable attackers to execute arbitrary JavaScript in the context of affected users' browsers.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings