CVE · Medium

CVE-2025-14481 — Yoast SEO – Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 26.6

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-14481 Yoast SEO – Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 26.6 Missing Authorization Medium 4.3 < 26.6 26.6 2026-05-26

CVE-2025-14481

The Yoast SEO plugin for WordPress has an insecure direct object reference vulnerability in all versions up to 26.5. The issue arises because the Meta Search REST API endpoint lacks proper authorization checks, allowing authenticated users with at least Contributor-level access to retrieve sensitive SEO metadata from any post, regardless of ownership or visibility status.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.