CVE Database /
CVE-2025-11241
CVE · Medium
CVE-2025-11241 — Yoast SEO Premium [wordpress-seo-premium] >= 25.7 - < 26.0
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-11241
|
Yoast SEO Premium [wordpress-seo-premium] >= 25.7 - < 26.0 |
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) |
Medium
6.4
|
25.7–26.0
|
26.0 |
2025-10-02 |
—
|
CVE-2025-11241
A security flaw exists in the Yoast SEO Premium plugin for WordPress, affecting versions 25.7 through 25.9. The issue arises from an incorrectly formulated regular expression used to strip attributes from post content, allowing attackers to inject malicious HTML attributes and potentially execute scripts. A user with at least Contributor privileges can exploit this vulnerability by crafting a post containing a malicious JavaScript payload.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings