CVE-2021-24153: Yoast SEO < 3.4.1 - Authenticated Stored Cross-Site Scripting (XSS)
Published Apr 5, 2021
·Updated
A Stored Cross-Site Scripting vulnerability was discovered in the Yoast SEO WordPress plugin before 3.4.1, which had built-in blacklist filters which were blacklisting Parenthesis as well as several functions such as alert but bypasses were found.
Affected Software
1 affected component
Yoast Yoast SEO WordPress<3.4.1
Event History
Apr 5, 2021
CVE Published
via MITRE·06:27 PM
Data Sourced
via MITRE·06:27 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Yoast SEO WordPress plugin vulnerability?
The vulnerability ID for this Yoast SEO WordPress plugin vulnerability is CVE-2021-24153.
2
What is the severity of CVE-2021-24153?
The severity of CVE-2021-24153 is medium.
3
What is the description of CVE-2021-24153?
CVE-2021-24153 is a Stored Cross-Site Scripting vulnerability in the Yoast SEO WordPress plugin before 3.4.1, which had built-in blacklist filters that were bypassed.
4
What software versions are affected by CVE-2021-24153?
The Yoast SEO WordPress plugin versions before 3.4.1 are affected by CVE-2021-24153.
5
How can I fix CVE-2021-24153?
To fix CVE-2021-24153, update your Yoast SEO WordPress plugin to version 3.4.1 or later.