What is CVE-2026-15425?
A Stored Cross-Site Scripting vulnerability via Post Slug has been found in the Yoast SEO plugin for WordPress (up to version 28.0). Authenticated users can inject malicious scripts due to insufficient input sanitization and output escaping. Updating to the latest version is strongly recommended.
Azərbaycanca: Yoast SEO (v28.0-ə qədər) WordPress plaginində 'Post Slug' sahəsi vasitəsilə Stored XSS zəifliyi aşkarlanıb. Buna görə autentifikasiyalı istifadəçi zərərli skript yerləşdirə bilər. Plaginin ən son versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the Yoast SEO plugin are affected by CVE-2026-15425?
This Stored XSS vulnerability affects the Yoast SEO plugin up to version 28.0.
What should be done to protect against CVE-2026-15425?
It is strongly recommended to update the Yoast SEO plugin to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.