WordPress Plugin Vulnerabilities

Yoast SEO < 2.2 - Authenticated Stored DOM XSS

Description

The "snippet preview" functionality of the Yoast WordPress SEO plugin was susceptible to cross-site scripting in versions before 2.2.

Proof of Concept

Affects Plugins

Fixed in 2.2

References

Classification

Type
XSS
CWE

Miscellaneous

Submitter
Charles Neill
Submitter website
Submitter twitter
Verified
No

Timeline

Publicly Published
2015-06-12 (about 10 years ago)
Added
2015-06-12 (about 10 years ago)
Last Updated
2021-01-19 (about 5 years ago)

Other