CVE · Medium

CVE-2025-11241 — Yoast SEO Premium [wordpress-seo-premium] >= 25.7 - < 26.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-11241 Yoast SEO Premium [wordpress-seo-premium] >= 25.7 - < 26.0 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) Medium 6.4 25.7–26.0 26.0 2025-10-02

CVE-2025-11241

A security flaw exists in the Yoast SEO Premium plugin for WordPress, affecting versions 25.7 through 25.9. The issue arises from an incorrectly formulated regular expression used to strip attributes from post content, allowing attackers to inject malicious HTML attributes and potentially execute scripts. A user with at least Contributor privileges can exploit this vulnerability by crafting a post containing a malicious JavaScript payload.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.