First published: Tue Jul 09 2019(Updated: )
The Yoast SEO plugin before 11.6-RC5 for WordPress does not properly restrict unfiltered HTML in term descriptions.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Yoast Yoast Seo | <11.6 | |
Yoast Yoast Seo | =11.6-rc1 | |
Yoast Yoast Seo | =11.6-rc2 | |
Yoast Yoast Seo | =11.6-rc3 | |
Yoast Yoast Seo | =11.6-rc4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-13478 is critical with a CVSS score of 9.8.
The affected software for CVE-2019-13478 is Yoast SEO plugin for WordPress versions up to 11.6.
CVE-2019-13478 allows attackers to inject unfiltered HTML in term descriptions, potentially leading to cross-site scripting (XSS) attacks.
To fix CVE-2019-13478, update the Yoast SEO plugin to version 11.6 or higher.
You can find more information about CVE-2019-13478 in the release notes of Yoast SEO plugin version 11.6-RC5 and the WPScan Vulnerability Database.