CVE · Medium

CVE-2024-4984 — Yoast SEO – Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 22.7

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-4984 Yoast SEO – Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 22.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 22.7 22.7 2024-05-14

CVE-2024-4984

The Yoast SEO plugin for WordPress contains a stored cross-site scripting vulnerability affecting versions 22.6 and earlier, stemming from inadequate sanitization of the 'display_name' author metadata field and insufficient output escaping. Attackers with at least contributor-level permissions can insert malicious scripts that will run when other users view pages containing the injected content. The vulnerability requires authentication but can be exploited by lower-privileged user roles to compromise website security.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.