CVE · Medium

CVE-2021-24153 — Yoast SEO – Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 3.4.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24153 Yoast SEO – Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 3.4.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.4.1 3.4.1 2016-08-02

CVE-2021-24153

The Yoast SEO plugin before version 3.4.1 contained a stored cross-site scripting flaw that allowed attackers to inject malicious scripts into the application. Although the plugin implemented a blacklist to block dangerous elements including parentheses and functions like alert, researchers identified methods to circumvent these restrictions. This vulnerability could enable attackers to execute arbitrary JavaScript in the context of affected users' browsers.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.