CVE Database /
CVE-2025-14481
CVE · Medium
CVE-2025-14481 — Yoast SEO – Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 26.6
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-14481
|
Yoast SEO – Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 26.6 |
Missing Authorization |
Medium
4.3
|
< 26.6
|
26.6 |
2026-05-26 |
—
|
CVE-2025-14481
The Yoast SEO plugin for WordPress has an insecure direct object reference vulnerability in all versions up to 26.5. The issue arises because the Meta Search REST API endpoint lacks proper authorization checks, allowing authenticated users with at least Contributor-level access to retrieve sensitive SEO metadata from any post, regardless of ownership or visibility status.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings