WP Clinic
Log in Sign up

CVE · Medium

CVE-2025-11241 — Yoast SEO Premium [wordpress-seo-premium] >= 25.7 - < 26.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-11241 Yoast SEO Premium [wordpress-seo-premium] >= 25.7 - < 26.0 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) Medium 6.4 25.7–26.0 26.0 2025-10-02

CVE-2025-11241

The Yoast SEO Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions 25.7 to 25.9 due to a flawed regex used to remove an attribute in post content, which can be abused to inject arbitrary HTML attributes, including JavaScript event handlers. This vulnerability allows a user with Contributor access or higher to create a post containing a malicious JavaScript payload.

Source: CVE.org

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.